ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 185 - SAP-C02 discussion

Report
Export

A company is using an organization in AWS Organizations to manage hundreds of AWS accounts. A solutions architect is working on a solution to provide baseline protection for the Open Web Application Security Project (OWASP) top 10 web application vulnerabilities. The solutions architect is using AWS WAF for all existing and new Amazon CloudFront distributions that are deployed within the organization.

Which combination of steps should the solutions architect take to provide the baseline protection? (Select THREE.)

A.
Enable AWS Config in all accounts.
Answers
A.
Enable AWS Config in all accounts.
B.
Enable Amazon GuardDuty in all accounts.
Answers
B.
Enable Amazon GuardDuty in all accounts.
C.
Enable all features for the organization.
Answers
C.
Enable all features for the organization.
D.
Use AWS Firewall Manager to deploy AWS WAF rules in all accounts for all CloudFront distributions.
Answers
D.
Use AWS Firewall Manager to deploy AWS WAF rules in all accounts for all CloudFront distributions.
E.
Use AWS Shield Advanced to deploy AWS WAF rules in all accounts for all CloudFront distributions.
Answers
E.
Use AWS Shield Advanced to deploy AWS WAF rules in all accounts for all CloudFront distributions.
F.
Use AWS Security Hub to deploy AWS WAF rules in all accounts for all CloudFront distributions.
Answers
F.
Use AWS Security Hub to deploy AWS WAF rules in all accounts for all CloudFront distributions.
Suggested answer: C, D, E

Explanation:

Enabling all features for the organization will enable using AWS Firewall Manager to centrally configure and manage firewall rules across multiple AWS accounts1. Using AWS Firewall Manager to deploy AWS WAF rules in all accounts for all CloudFront distributions will enable providing baseline protection for the OWASP top 10 web application vulnerabilities2. AWS Firewall Manager supports AWS WAF rules that can help protect against common web exploits such as SQL injection and cross-site scripting3. Configuring redirection of HTTP requests to HTTPS requests in CloudFront will enable encrypting the data in transit using SSL/TLS.

asked 16/09/2024
ANIKET PATEL
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first