Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SCS-C02 Topic 7 Question 19 Discussion

Actual exam question for Amazon's SCS-C02 exam
Question #: 19
Topic #: 7
[All SCS-C02 Questions]

A company's data scientists want to create AI/ML training models using Amazon SageMaker. The training models will use large datasets in an Amazon S3 bucket. The datasets contain sensitive information. On average, the data scientists need 30 days to train models. The S3 bucket has been secured appropriately. The company's data retention policy states that all data older than 45 days must be removed from the S3 bucket.

Show Suggested Answer Hide Answer
Suggested Answer: C

To mitigate a credential stuffing attack against a web-based application behind an Application Load Balancer (ALB), creating an AWS WAF web ACL with a custom rule to block requests containing the known malicious user agent string is an effective solution. This approach allows for precise targeting of the attack vector (the user agent string of the device emulator) without impacting legitimate users. AWS WAF provides the capability to inspect HTTP(S) requests and block those that match defined criteria, such as specific strings in the user agent header, thereby preventing malicious requests from reaching the application.


Contribute your Thoughts:

Viola
10 days ago
Option C is a neat solution, but I'm not sure if it's the most efficient way to manage the data. What if the training needs to be done more frequently?
upvoted 0 times
...
Vernell
14 days ago
Option B looks good, but creating an S3 event notification for each PutObject operation could get expensive if there are a lot of uploads.
upvoted 0 times
...
Brett
15 days ago
Hmm, that's a good point. Option B does offer more automation which can be helpful in the long run.
upvoted 0 times
...
Argelia
15 days ago
Option A seems like the easiest solution, but it may not be flexible enough if the training needs change in the future.
upvoted 0 times
...
Kenny
19 days ago
I disagree, I believe option B is better. It provides more control and automation.
upvoted 0 times
...
Brett
25 days ago
I think option A is the best choice. It's simple and straightforward.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77