ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 316 - SCS-C01 discussion

Report
Export

Your company currently has a set of EC2 Instances hosted in a VPC. The IT Security department is suspecting a possible DDos attack on the instances. What can you do to zero in on the IP addresses which are receiving a flurry of requests. Please select:

A.
Use VPC Flow logs to get the IP addresses accessing the EC2 Instances
Answers
A.
Use VPC Flow logs to get the IP addresses accessing the EC2 Instances
B.
Use AWS Cloud trail to get the IP addresses accessing the EC2 Instances
Answers
B.
Use AWS Cloud trail to get the IP addresses accessing the EC2 Instances
C.
Use AWS Config to get the IP addresses accessing the EC2 Instances
Answers
C.
Use AWS Config to get the IP addresses accessing the EC2 Instances
D.
Use AWS Trusted Advisor to get the IP addresses accessing the EC2 Instances
Answers
D.
Use AWS Trusted Advisor to get the IP addresses accessing the EC2 Instances
Suggested answer: A

Explanation:

With VPC Flow logs you can get the list of IP addresses which are hitting the Instances in your VPC You can then use the information in the logs to see which external IP addresses are sending a flurry of requests which could be the potential threat foi a DDos attack.

Option B is incorrect Cloud Trail records AWS API calls for your account. VPC FLowlogs logs network traffic for VPC, subnets. Network interfaces etc. As per AWS,

VPC Flow Logs is a feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC where as AWS CloudTrail, is a service that captures API calls and delivers the log files to an Amazon S3 bucket that you specify.

Option C is invalid this is a config service and will not be able to get the IP addresses

Option D is invalid because this is a recommendation service and will not be able to get the IP addresses For more information on VPC Flow Logs, please visit the following URL:

https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/flow-logs.htmlThe correct answer is: Use VPC Flow logs to get the IP addresses accessing the EC2 Instances Submityour Feedback/Queries to our Experts

asked 16/09/2024
Dinu Jose Varghese
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first