Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 8 Topic 1 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 8 Topic 1 Discussion

SCS-C02 Exam Topic 1 Question 8 Discussion:
Question #: 8
Topic #: 1

A company hosts its public website on Amazon EC2 instances behind an Application Load Balancer (ALB). The website is experiencing a global DDoS attack by a specific loT device brand that has a unique user agent.

A security engineer is creating an AWS WAF web ACL and will associate the web ACL with the ALB. The security engineer must implement a rule statement as part of the web ACL to block the requests. The rule statement must mitigate the current attack and future attacks from these loT devices without blocking requests from customers.

Which rule statement will meet these requirements?


A.

Use an IP set match rule statement that includes the IP address for loT devices from the user agent.


B.

Use a geographic match rule statement. Configure the statement to block countries that the loT devices are located in.


C.

Use a rate-based rule statement. Set a rate limit that is equal to the number of requests that are coming from the loT devices.


D.

Use a string match rule statement that includes details of the loT device brand from the user agent.


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.