Soru

Zorluk: KolayEdge and DDoS Protection

A startup is hosting a public-facing web application using an Amazon CloudFront distribution as the entry point. The startup needs to protect the application from common web exploits, such as SQL injection, and secure the infrastructure against sophisticated network-layer Distributed Denial of Service (DDoS) attacks. Which TWO actions should the Solutions Architect take to meet these requirements?

  1. Associate an AWS WAF web ACL with the Amazon CloudFront distribution to filter application-layer exploits.Cevap
  2. Enable AWS Shield Advanced on the Amazon CloudFront distribution to provide enhanced protection against network and transport layer DDoS attacks.Cevap
  3. C
    Configure a security group on the Amazon CloudFront distribution to restrict inbound traffic to specific source IP ranges.
  4. D
    Create stateless Network Access Control List (NACL) rules at the subnet level to automatically block SQL injection and cross-site scripting attacks.
  5. E
    Use AWS Shield Standard to inspect incoming HTTP requests and automatically block cross-site scripting (XSS) attacks.

Cevap

Associate an AWS WAF web ACL with the Amazon CloudFront distribution and enable AWS Shield Advanced on the Amazon CloudFront distribution.
The correct options are associating an AWS WAF web ACL with the CloudFront distribution and enabling AWS Shield Advanced on the distribution. AWS WAF provides protection against Layer 7 application exploits like SQL injection by inspecting request payloads. AWS Shield Advanced provides comprehensive protection against Layer 3 and Layer 4 DDoS attacks for CloudFront distributions.

Adım Adım Çözüm

1
Determine the service needed to block application-layer (Layer 7) exploits such as SQL injection at the edge.
AWS WAF is selected because it integrates with CloudFront to inspect HTTP/HTTPS request bodies and headers.
AWS WAF is designed specifically to prevent application-layer exploits.
2
Determine the service needed to defend against infrastructure-layer (Layer 3 and 4) DDoS attacks targeting CloudFront.
AWS Shield Advanced is selected to provide advanced network and transport layer DDoS mitigation.
AWS Shield Advanced offers enhanced, tailored protection for edge services compared to AWS Shield Standard.

Anahtar Kavram

Combining AWS WAF for Layer 7 application security and AWS Shield Advanced for Layer 3 and 4 infrastructure DDoS protection at the CloudFront edge.
Tahmini Süre:1m 30s
Bu soruyu puanla