ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 204 - SAA-C03 discussion

Report
Export

A company is running a publicly accessible serverless application that uses Amazon API Gateway and AWS Lambd a. The application's traffic recently spiked due to fraudulent requests from botnets. Which steps should a solutions architect take to block requests from unauthorized users? (Select TWO.)

A.
Create a usage plan with an API key that is shared with genuine users only.
Answers
A.
Create a usage plan with an API key that is shared with genuine users only.
B.
Integrate logic within the Lambda function to ignore the requests from fraudulent IP addresses.
Answers
B.
Integrate logic within the Lambda function to ignore the requests from fraudulent IP addresses.
C.
Implement an AWS WAF rule to target malicious requests and trigger actions to filter them out.
Answers
C.
Implement an AWS WAF rule to target malicious requests and trigger actions to filter them out.
D.
Convert the existing public API to a private API. Update the DNS records to redirect users to the new API endpoint.
Answers
D.
Convert the existing public API to a private API. Update the DNS records to redirect users to the new API endpoint.
E.
Create an IAM role for each user attempting to access the API. A user will assume the role when making the API call.
Answers
E.
Create an IAM role for each user attempting to access the API. A user will assume the role when making the API call.
Suggested answer: A, C

Explanation:

https://docs.aws.amazon.com/apigateway/latest/developerguide/api-gateway-api-usageplans.html#:~:text=Don%27t%20rely%20on%20API%20keys%20as%20your%20only%20means%20of%20authentication%20and%20authorization% 20for%20your%20APIs

https://docs.aws.amazon.com/apigateway/latest/developerguide/api-gateway-api-usage-plans.html

asked 16/09/2024
Alois Braid
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first