AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceHard

A healthcare provider is deploying a new patient portal application on AWS. Due to HIPAA compliance, all sensitive patient data must be encrypted in transit and at rest, and only authorized internal users and services should be able to access the application. The DevOps team needs to ensure that the application's API endpoints are exposed securely, allowing only authenticated and authorized traffic, and preventing common web vulnerabilities. Which combination of AWS services should be used to achieve secure API exposure and access control?

  1. AApplication Load Balancer with Security Groups and NACLs.
  2. BAWS Global Accelerator with Network Load Balancer for high performance.
  3. CAmazon CloudFront with AWS Shield Advanced for DDoS protection.
  4. DAmazon API Gateway with AWS WAF and IAM/Cognito Authorizers.
Show answer & explanation

Correct answer: D. Amazon API Gateway with AWS WAF and IAM/Cognito Authorizers.

Amazon API Gateway provides a fully managed service for creating, publishing, maintaining, monitoring, and securing APIs. It inherently supports TLS for encryption in transit. Integrating AWS WAF protects against common web exploits. IAM or Cognito Authorizers provide robust authentication and authorization mechanisms, ensuring only authorized users/services can access the API.

Why the other options are wrong

  • A. ALB provides load balancing and Security Groups/NACLs offer network-level filtering, but it lacks the API management features, built-in authorizers, and direct WAF integration at the API layer that API Gateway provides.
  • B. Global Accelerator and NLB focus on network performance and availability, not API management, authentication, or web exploit protection.
  • C. CloudFront is a CDN and Shield Advanced is for DDoS protection; while good for performance and some security, they don't provide API management, authentication, or granular authorization for API endpoints.

Secure API Exposure

The process of making API endpoints available while implementing robust security measures, including authentication, authorization, encryption, and protection against common web vulnerabilities.

  • Crucial for data protection and compliance.
  • Involves multiple layers of security.
  • AWS API Gateway is a key service for this.

Memory trick: API Gateway is the secure 'front door' for your application, with WAF and IAM guards.

More Security and Compliance questions