AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium

A media streaming platform needs to protect its content delivery infrastructure on AWS from distributed denial-of-service (DDoS) attacks. The platform uses Amazon CloudFront, Application Load Balancers (ALB), and Amazon EC2 instances. The company requires advanced DDoS protection, including automatic inline mitigation, near real-time visibility into attacks, and cost protection for scaling resources during an attack. Which AWS service should be implemented?

  1. AAmazon GuardDuty
  2. BAWS WAF
  3. CAWS Config
  4. DAWS Shield Advanced
Show answer & explanation

Correct answer: D. AWS Shield Advanced

AWS Shield Advanced provides comprehensive DDoS protection for AWS applications, including automatic inline mitigation, advanced attack visibility through CloudWatch metrics and logs, and cost protection against scaling charges incurred due to a DDoS attack. It is designed to protect resources like CloudFront, ALBs, and EC2 instances from a wide range of DDoS attacks.

Why the other options are wrong

  • A. Amazon GuardDuty is a threat detection service, not a DDoS protection service.
  • B. AWS WAF protects against application-layer exploits and can help with *some* DDoS, but does not offer the same level of comprehensive, automatic, and cost-protected DDoS mitigation as Shield Advanced.
  • C. AWS Config monitors resource configurations for compliance, but does not provide DDoS protection.

AWS Shield Advanced

A managed DDoS protection service that provides enhanced protections for applications running on AWS beyond the standard protections of AWS Shield Standard.

  • Always-on detection and automatic inline mitigations.
  • Visibility into attacks via CloudWatch.
  • Cost protection against scaling surges during attacks.

Memory trick: SHIELD 'ADVANCED' defends against 'DDOS' with 'COST PROTECTION'.

More Network Security, Compliance, and Governance questions