ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 172 - SCS-C01 discussion

Report
Export

A distributed web application is installed across several EC2 instances in public subnets residing in two Availability Zones. Apache logs show several intermittent brute-force attacks from hundreds of IP addresses at the layer 7 level over the past six months.

What would be the BEST way to reduce the potential impact of these attacks in the future?

A.
Use custom route tables to prevent malicious traffic from routing to the instances.
Answers
A.
Use custom route tables to prevent malicious traffic from routing to the instances.
B.
Update security groups to deny traffic from the originating source IP addresses.
Answers
B.
Update security groups to deny traffic from the originating source IP addresses.
C.
Use network ACLs.
Answers
C.
Use network ACLs.
D.
Install intrusion prevention software (IPS) on each instance.
Answers
D.
Install intrusion prevention software (IPS) on each instance.
Suggested answer: D

Explanation:

https://docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html NACL has limit 20 (canincrease to maximum 40 rule), and more rule will make more low-latency

asked 16/09/2024
AHOPkos Varga
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first