QuestionQ29

Detection

A company's public website includes an Application Load Balancer (ALB), a group of Amazon EC2 instances running a stateless application behind the ALB, and an Amazon DynamoDB table that the application reads from. The company is concerned about malicious scanning and DDoS attacks. The company needs to enforce a restriction so that each client IP address can read the data only 3 times during any 5-minute period.

Which solution will satisfy this requirement with the LEAST effort?

Explanation

AWS WAF rate-based rules cannot be configured with a threshold as low as 3 requests: the current minimum is 10, and AWS documents that this mechanism is not intended to provide precise request-rate limiting. Enforcing exactly three reads for each source IP in a rolling 5-minute window therefore requires application-level tracking and rejection of additional requests. A notification-only Lambda workflow and DynamoDB TTL/read-capacity changes do not enforce this per-IP access limit.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!