ExamQuestions.com

Register
Login
AWS Certified DevOps Engineer Professional Exam Questions

Amazon

AWS Certified DevOps Engineer Professional

488 / 500

Question 488:

You are a DevOps engineer in a company. There will be a security audit in the company and the security team asks you to provide evidence that the web applications in AWS are protected from the most critical attacks mentioned in “Open Web Application Security Project (OWASP) Top 10”. For example, web application vulnerabilities such as SQL injection and Cross-Site Scripting (XSS) should be mitigated by an approach. This approach should also be cost-effective and simple to implement. Which of the following options would you select?

Answer options:

A.Create a web ACL in AWS WAF and add a rule from AWS Marketplace that can mitigate and minimize the OWASP Top 10 vulnerabilities and threats.
B.Set up AWS WAF and use a CloudFormation stack to create a Web ACL along with condition types and rules to protect the web applications in AWS.
C.Enable AWS Shield Advanced which can protect the AWS EC2 instances and Lambda functions against web attacks that belong to OWASP Top 10.
D.Set up AWS Inspector and include the “OWASP Top 10” rule package in the assessment to mitigate the major vulnerabilities.