Combine Lambda provisioned concurrency, RDS Reserved Instances, and WAF on CloudFront
A company runs an ecommerce web application on AWS. The web application is hosted as a static website on Amazon S3 with Amazon CloudFront for content delivery. An Amazon API Gateway API invokes AWS Lambda functions to handle user requests and order processing for the web application The Lambda functions store data in an Amazon ROS for MySQL DB cluster that uses On-Demand instances. The DB cluster usage has been consistent in the past 12 months. Recently, the website has experienced SQL injection and web exploit attempts. Customers also report that order processing time has increased during periods of peak usage. During these periods, the Lambda functions often have cold starts. As the company grows, the company needs to ensure scalability and low-latency access during traffic peaks. The company also must optimize the database costs and add protection against the SQL injection and web exploit attempts. Which solution will meet these requirements?
Community Votes
75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Each requirement maps to one purpose-built service: provisioned concurrency removes cold starts, Reserved Instances cut cost for predictable steady usage, and WAF attached to CloudFront inspects HTTP requests for injection patterns.
A static S3 site behind CloudFront calls API Gateway and Lambda functions that persist to an Aurora MySQL cluster running On-Demand instances with steady 12-month usage. Peak traffic causes cold starts and slow order processing, and the site is under SQL injection and exploit attempts.
Reaching for AWS Shield Advanced. Shield Advanced provides a subscription-based DDoS protection layer for the distribution but does not inspect request payloads for SQL injection, so it does not address the stated web exploit requirement.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Provisioned concurrency keeps a set of Lambda execution environments initialized, so order processing no longer waits on cold starts during peaks. Because the database usage has been consistent for twelve months, RDS Reserved Instances convert that predictable baseline into a lower hourly rate with no architectural change. AWS WAF attached to the CloudFront distribution inspects incoming requests at the layer where the static site is served, and its managed rules include SQL injection and known exploit patterns, so malicious requests can be blocked before they reach Lambda. Together the three address compute latency, database cost, and application-layer protection in one set of changes.Why the Other Options Are Wrong
A: Raising the Lambda timeout does not remove cold starts, so the latency requirement is not addressed at all. B: Amazon Inspector cannot be integrated with CloudFront to protect against SQL injection, and migrating to Redshift is an analytical warehouse rather than an operational transactional store. C: Aurora Serverless is a reasonable serverless option but does not deliver the cost saving of Reserved Instances for steady twelve-month usage, and AWS Shield Advanced is a DDoS protection subscription rather than a payload-inspecting web application firewall, so it does not block SQL injection attempts.Community Comment Notes
The community voted 75 to 25 for D over C, and the deciding argument was that WAF is the service that inspects requests for SQL injection and web exploits while Shield Advanced focuses on layer 3 and 4 DDoS protection. A commenter also pointed out that the steady twelve-month usage pattern in the question is the explicit signal to choose Reserved Instances over Serverless.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →