Q415. A company has a serverless application that is deployed on AWS. The application uses an Amazon API Gateway REST API and AWS Lambda to receive and process requests from other applications within the company's on- premises

欢迎免费使用小程序搜题/刷题/查看解析,提升学历,成考自考报名,论文代写、论文查重请加客服微信skr-web


Q415. A company has a serverless application that is deployed on AWS. The application uses an Amazon API Gateway REST API and AWS Lambda to receive and process requests from other applications within the company's on- premises network. The application uses a preshared API key as the authentication method. A recent security review showed that the application was accessible from anywhere on the internet. The company's security policy states that requests can be accepted only from the company's on- premises network.What should a solutions architect recommend to meet this requirement?

A.Configure a security group with rules to allow traffic only from within the company's public IP address range.Attach the security group to the API Gateway API. and redeploy the API
B.Create a Lambda function to inspect the requests and deny the execute- api:Invoke action if the request is not from within the company's public IP address range Configure the Lambda function as a custom authorizer for the API Gateway API Redeploy the API
C.Create a resource policy with a statement to deny the execute-api:Invoke action if the aws:Sourcelp attribute is not from within the company's public IP address range Attach that resource policy to the API Gateway API Redeploy the API.
D.Configure a request validator for API Gateway to inspect the requests and deny the execute-api Invoke action if the aws:Sourcelp attribute is not from within the company's public IP address range Redeploy the API Gateway API
正确答案C
访客
邮箱
网址

通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作


  • 自动写文案
  • 自动写小说
  • 马上扫码让Ai帮你完成工作
通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作

  • 自动写论文
  • 自动写软件
  • 我不是人,但是我比人更聪明,我是强大的Ai
Top