ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 460 - SCS-C01 discussion

Report
Export

A Security Engineer receives alerts that an Amazon EC2 instance on a public subnet is under an SFTP brute force attack from a specific IP address, which is a known malicious bot. What should the Security Engineer do to block the malicious bot?

A.
Add a deny rule to the public VPC security group to block the malicious IP
Answers
A.
Add a deny rule to the public VPC security group to block the malicious IP
B.
Add the malicious IP to AWS WAF backhsted IPs
Answers
B.
Add the malicious IP to AWS WAF backhsted IPs
C.
Configure Linux iptables or Windows Firewall to block any traffic from the malicious IP
Answers
C.
Configure Linux iptables or Windows Firewall to block any traffic from the malicious IP
D.
Modify the hosted zone in Amazon Route 53 and create a DNS sinkhole for the malicious IP
Answers
D.
Modify the hosted zone in Amazon Route 53 and create a DNS sinkhole for the malicious IP
Suggested answer: D
asked 16/09/2024
Vladimir Kosintsov
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first