QuestionQ29

Security Operations

A company notices that cloud environment costs increased after using a new serverless solution based on API requests. Many invalid requests from unknown IPs were found, often within a short time. Which of the following solutions would most likely solve this issue, reduce cost, and improve security?

Explanation

To prevent cost exhaustion from invalid requests, implement both API authentication (to verify legitimate callers) and rate limiting (to prevent abuse even from authenticated users or misconfigured clients). This dual approach stops both unauthorized and abusive traffic, reducing costs and improving security. Digital certificates alone do not prevent volumetric abuse; IP-based filtering is bypassed easily.

Community Discussion

No comments yet. Be the first to start the discussion!