Medium1 markMultiple Choice

AWS SAP-C02 · Question 59 · Domain 3.2: Security Improvement

A company is using AWS WAF to protect their web application. They are noticing a high volume of requests from malicious IP addresses that are constantly changing. They want to automatically block IP addresses that exhibit anomalous behavior, such as scanning for vulnerabilities. Which AWS WAF feature should they use?

Answer options:

A.

Create a custom Lambda function to parse CloudFront logs and update WAF IP sets.

B.

AWS WAF Bot Control and Managed Rules for IP Reputation.

C.

AWS Shield Standard.

D.

Amazon GuardDuty.

How to approach this question

Leverage AWS Managed Rules for WAF.

Full Answer

B.AWS WAF Bot Control and Managed Rules for IP Reputation.✓ Correct
AWS WAF Bot Control and Managed Rules for IP Reputation.
AWS WAF Managed Rules provide pre-configured rule sets maintained by AWS, including IP reputation lists (blocking known bad actors) and Bot Control (blocking anomalous scanning behavior).

Common mistakes

Building custom log parsers instead of using Managed Rules.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

75 questions · hints · full answers · grading

More questions from this exam