A media company is hosting a popular streaming service on AWS, utilizing a fleet of EC2 instances behind an Application Load Balancer (ALB). The company is concerned about Distributed Denial of Service (DDoS) attacks and common web exploits targeting their application. They need a solution that provides immediate, automated protection against these threats without manual intervention and can scale with their traffic. Which AWS service combination should be implemented for this scenario?
- AImplement AWS Shield Advanced for enhanced DDoS protection and integrate AWS WAF with the Application Load Balancer to mitigate common web exploits.
- BDeploy a third-party Web Application Firewall (WAF) appliance on EC2 instances and use Network ACLs to block suspicious IP addresses.
- CUse Amazon GuardDuty for threat detection and AWS Config for continuous monitoring of security group changes.
- DConfigure AWS Shield Standard for DDoS protection and implement Security Groups on the EC2 instances to filter malicious traffic patterns.
Show answer & explanationAnswer & explanation
Correct answer: A. Implement AWS Shield Advanced for enhanced DDoS protection and integrate AWS WAF with the Application Load Balancer to mitigate common web exploits.
AWS Shield Advanced provides comprehensive DDoS protection for applications, offering always-on detection and automatic inline mitigations. AWS WAF, when integrated with an Application Load Balancer, provides protection against common web exploits (like SQL injection and cross-site scripting) and allows for custom rules, fulfilling the requirement for automated protection against both DDoS and web exploits.
Why the other options are wrong
- B. Deploying a third-party WAF appliance on EC2 adds operational overhead and doesn't offer the same integrated, always-on DDoS protection as Shield Advanced. Network ACLs are stateless and operate at the network layer, not suitable for application-layer exploit mitigation.
- C. GuardDuty and Config are valuable security services but primarily for threat detection and compliance monitoring, respectively. They do not provide direct, inline protection against DDoS attacks or common web exploits for a streaming service.
- D. Shield Standard offers basic DDoS protection but doesn't protect against application-layer attacks. Security Groups are stateful firewalls but are not designed for deep packet inspection or web exploit mitigation.
Web Application Security Stack
A combination of AWS services designed to protect web applications against various threats, including DDoS attacks and common web exploits, offering layered security and automated mitigation.
- AWS Shield provides DDoS protection (Standard for basic, Advanced for enhanced).
- AWS WAF protects against common web exploits (SQL injection, XSS) at the application layer.
- WAF integrates with Application Load Balancer, CloudFront, and API Gateway.
- This combination offers automated, scalable, and managed security.
Memory trick: For web apps, 'Shield' blocks the big waves (DDoS), and 'WAF' catches the 'bad fish' (exploits).