Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 93 Topic 10 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 93 Topic 10 Discussion

SCS-C02 Exam Topic 10 Question 93 Discussion:
Question #: 93
Topic #: 10

A Security Engineer receives alerts that an Amazon EC2 instance on a public subnet is under an SFTP brute force attack from a specific IP address, which is a known malicious bot. What should the Security Engineer do to block the malicious bot?


A.

Add a deny rule to the public VPC security group to block the malicious IP


B.

Add the malicious IP to IAM WAF backhsted IPs


C.

Configure Linux iptables or Windows Firewall to block any traffic from the malicious IP


D.

Modify the hosted zone in Amazon Route 53 and create a DNS sinkhole for the malicious IP


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.