ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 518 - SCS-C01 discussion

Report
Export

A company is hosting multiple applications within a single VPC in its AWS account. The applications are running behind an Application Load Balancer that is associated with an AWS WAF web ACL. The company's security team has identified that multiple port scans are originating from a specific range of IP addresses on the internet. A security engineer needs to deny access from the offending IP addresses.

Which solution will meet these requirements?

A.
Modify the AWS WAF web ACL with an IP set match rule statement to deny incoming requests from the IP address range.
Answers
A.
Modify the AWS WAF web ACL with an IP set match rule statement to deny incoming requests from the IP address range.
B.
Add a rule to all security groups to deny the incoming requests from the IP address range.
Answers
B.
Add a rule to all security groups to deny the incoming requests from the IP address range.
C.
Modify the AWS WAF web ACL with a rate-based rule statement to deny the incoming requests from the IP address range.
Answers
C.
Modify the AWS WAF web ACL with a rate-based rule statement to deny the incoming requests from the IP address range.
D.
Configure the AWS WAF web ACL with regex match conditions. Specify a pattern set to deny the incoming requests based on the match condition
Answers
D.
Configure the AWS WAF web ACL with regex match conditions. Specify a pattern set to deny the incoming requests based on the match condition
Suggested answer: A

Explanation:

Note that the IP is known and the question wants us to deny access from that particular address and so we can use IP set match policy of WAF to block access.

asked 16/09/2024
Samori Augusto
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first