What should the Security Engineer do to meet these requirements?

1 Comment

  1. Benjamin
    Author

    As far as I’m aware, the answer is:
    Create an Application Load Balancer with the existing EC2 instances as a target group. Create an AWS WAF web ACL containing rules that protect the application from this attack, then apply it to the ALB. Test to ensure the vulnerability has been mitigated, then redirect the Route 53 records to point to the ALB. Update security groups on the EC2 instances to prevent direct access from the internet.

Leave a Reply

Your email address will not be published. Required fields are marked *

19 + 18 =