ETExamTower
Q15Network Security, Compliance, and GovernanceMultiple answers

A gaming company runs in a single AWS Region. Its architecture includes an Application Load Balancer (ALB) and Amazon EC2 instances in an Auto Scaling group that host a frontend application. The company uses AWS WAF integrated with the ALB. The ALB has one security group associated with it. The company uses AWS Network Firewall with stateful rules. The company has configured Network ACLs. The company needs to automatically block access for game users who violate particular rules. Problematic users must be blocked temporarily for 1 to 2 hours. The company’s software can identify the source IP addresses of problematic users. The company has built a serverless solution to store those IP addresses in Amazon DynamoDB. The company wants to use its existing serverless architecture to automatically block the problematic users. Which solution meets these requirements in the **MOST** scalable way? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
A
50% (2)
E
50% (2)
B
0% (0)
C
0% (0)
D
0% (0)
Discussion · 1
A, E 1
* A — Correct: Use an AWS WAF IP set and a WAF block rule. This is ideal because the ALB already uses AWS WAF, and the app identifies bad source IPs. AWS WAF IP sets are designed for matching web requests against IP lists. * E — Correct: Use an AWS Network Firewall stateless rule to drop traffic from those source IPs. Network Firewall rule groups can be updated programmatically, and stateless rules can drop packets before deeper inspection.