AWS Certified Solutions Architect – Associate (SAA-C02) — Question 162

A solutions architect is performing a security review of a recently migrated workload. The workload is a web application that consists of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The solutions architect must improve the security posture and minimize the impact of a DDoS attack on resources.
Which solution is MOST effective?

Answer options

Correct answer: A

Explanation

Answer A is the most effective because it incorporates AWS WAF with rate-based rules to directly mitigate DDoS attacks while routing traffic through CloudFront, which offers additional DDoS protection. The other options involve more complex setups and do not provide the same level of immediate protection against DDoS attacks as using WAF and CloudFront together.