AWS SAP-C02 · Question 08 · Domain 1.2: Security Controls
An architecture includes an Application Load Balancer (ALB) fronting an Amazon ECS cluster. The security team wants to block malicious IP addresses, prevent SQL injection attacks, and ensure that only traffic from the ALB can reach the ECS tasks. Which combination of services and configurations should be used?
Answer options:
Attach AWS Shield Advanced to the ECS cluster. Use Network ACLs to block IPs.
Attach AWS WAF to the ALB. Configure ECS security groups to only allow ingress from the ALB security group.
Deploy AWS Network Firewall in front of the ALB. Use ECS security groups to allow 0.0.0.0/0.
Attach AWS WAF to the ECS cluster directly. Use ALB security groups to block IPs.
75 questions · hints · full answers · grading