An ecommerce website was down for 1 hour following a DDoS attack. Users were unable to connectto the website during the attack period. The ecommerce company's security team is worried aboutfuture potential attacks and wants to prepare for such events. The company needs to minimizedowntime in its response to similar attacks in the future.Which steps would help achieve this? (Select TWO.)
A company uses an organization in AWS Organizations to manage multiple AWS accounts. A securityengineer creates a WAF policy in AWS Firewall Manager in the us-east-1 Region. The securityengineer sets the policy scope to apply to resources that are tagged withWAF-protected:truein oneof the member accounts in the organization. The security engineer sets up a configuration toautomatically remediate any noncompliant resources.In a member account, the security engineer attempts to protect an Amazon API Gateway REST API inthe us-east-1 Region by using a web ACL. However, after several minutes, the REST API is still notassociated with the web ACL.What is the likely cause of this issue?
A company needs a cloud-based, managed desktop solution for its workforce of remote employees. The
company wants to ensure that the employees can access the desktops only by using company-provided
devices. A security engineer must design a solution that will minimize cost and management overhead.
Which solution will meet these requirements?
A company's web application is hosted on Amazon EC2 instances running behind an Application Load
Balancer (ALB) in an Auto Scaling group. An AWS WAF web ACL is associated with the ALB. AWS
CloudTrail is enabled and stores logs in Amazon S3 and Amazon CloudWatch Logs. The operations team has observed some EC2 instances reboot at random. After rebooting, all access logs on
the instances have been deleted. During an investigation, the operations team found that each reboot happened
just after a PHP error occurred on the new-user-creation.php file. The operations team needs to view log
information to determine if the company is being attacked.
Which set of actions will identify the suspect attacker's IP address for future occurrences?
A company runs workloads in an AWS account. A security engineer observes some unusual findings in
Amazon GuardDuty. The security engineer wants to investigate a specific IAM role and generate an
investigation report. The report must contain details about anomalous behavior and any indicators of
compromise.
Which solution will meet these requirements?