Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SAP-C02 Exam - Topic 1 Question 73 Discussion

A company uses a load balancer to distribute traffic to Amazon EC2 instances in a single Availability Zone. The company is concerned about security and wants a solutions architect to re-architect the solution to meet the following requirements:*Inbound requests must be filtered for common vulnerability attacks.*Rejected requests must be sent to a third-party auditing application.*All resources should be highly available.Which solution meets these requirements?
D) Configure a Multi-AZ Auto Scaling group using the application's AMI. Create an Application Load Balancer (ALB) and select the previously created Auto Scaling group as the target. Create an Amazon Kinesis Data Firehose with a destination of the third-party auditing application. Create a web ACL in WAF. Create an AWS WAF using the WebACL and ALB then enable logging by selecting the Kinesis Data Firehose as the destination. Subscribe to AWS Managed Rules in AWS Marketplace, choosing the WAF as the subscriber.
A) Configure a Multi-AZ Auto Scaling group using the application's AMI. Create an Application Load Balancer (ALB) and select the previously created Auto Scaling group as the target. Use Amazon Inspector to monitor traffic to the ALB and EC2 instances. Create a web ACL in WAF. Create an AWS WAF using the web ACL and ALB. Use an AWS Lambda function to frequently push the Amazon Inspector report to the third-party auditing application.
B) Configure an Application Load Balancer (ALB) and add the EC2 instances as targets Create a web ACL in WAF. Create an AWS WAF using the web ACL and ALB name and enable logging with Amazon CloudWatch Logs. Use an AWS Lambda function to frequently push the logs to the third-party auditing application.
C) Configure an Application Load Balancer (ALB) along with a target group adding the EC2 instances as targets. Create an Amazon Kinesis Data Firehose with the destination of the third-party auditing application. Create a web ACL in WAF. Create an AWS WAF using the web ACL and ALB then enable logging by selecting the Kinesis Data Firehose as the destination. Subscribe to AWS Managed Rules in AWS Marketplace, choosing the WAF as the subscriber.

Amazon SAP-C02 Exam - Topic 1 Question 73 Discussion

Actual exam question for Amazon's SAP-C02 exam
Question #: 73
Topic #: 1
[All SAP-C02 Questions]

A company uses a load balancer to distribute traffic to Amazon EC2 instances in a single Availability Zone. The company is concerned about security and wants a solutions architect to re-architect the solution to meet the following requirements:

*Inbound requests must be filtered for common vulnerability attacks.

*Rejected requests must be sent to a third-party auditing application.

*All resources should be highly available.

Which solution meets these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: D

https://docs.aws.amazon.com/waf/latest/developerguide/marketplace-managed-rule-groups.html


Contribute your Thoughts:

0/2000 characters
Darrin
3 days ago
Multi-AZ sounds great, but is it really necessary for this setup?
upvoted 0 times
...
Jerlene
8 days ago
D looks like the best choice for high availability.
upvoted 0 times
...
Paz
13 days ago
Wait, why would you need Kinesis in C? Seems overkill.
upvoted 0 times
...
Yuriko
19 days ago
I think B is simpler and still meets the requirements.
upvoted 0 times
...
Mollie
24 days ago
Option A seems solid with the Auto Scaling and Inspector combo.
upvoted 0 times
...
Cora
29 days ago
I remember that AWS WAF is crucial for filtering out vulnerabilities, but I’m unsure if I should prioritize that over the other components mentioned in the options.
upvoted 0 times
...
Caitlin
1 month ago
I feel like using Kinesis Data Firehose is a good way to send logs to the auditing application, but I can't recall if it's the best choice here.
upvoted 0 times
...
Fanny
1 month ago
I think option B sounds familiar because it mentions enabling logging with CloudWatch, which we practiced in a similar scenario.
upvoted 0 times
...
Daniel
1 month ago
I remember we discussed the importance of using a Multi-AZ setup for high availability, but I'm not sure if it's necessary for this specific question.
upvoted 0 times
...

Save Cancel