Combine Lambda provisioned concurrency, RDS Reserved Instances, and WAF on CloudFront

Answer Correct answer: D — Use Lambda provisioned concurrency, RDS Reserved Instances, and AWS WAF integrated with CloudFront to block injection and exploit attempts.

A company runs an ecommerce web application on AWS. The web application is hosted as a static website on Amazon S3 with Amazon CloudFront for content delivery. An Amazon API Gateway API invokes AWS Lambda functions to handle user requests and order processing for the web application The Lambda functions store data in an Amazon ROS for MySQL DB cluster that uses On-Demand instances. The DB cluster usage has been consistent in the past 12 months. Recently, the website has experienced SQL injection and web exploit attempts. Customers also report that order processing time has increased during periods of peak usage. During these periods, the Lambda functions often have cold starts. As the company grows, the company needs to ensure scalability and low-latency access during traffic peaks. The company also must optimize the database costs and add protection against the SQL injection and web exploit attempts. Which solution will meet these requirements?

  1. Configure the Lambda functions to have an increased timeout value during peak periods. Use RDS Reserved Instances for the database. Use CloudFront and subscribe to AWS Shield Advanced to protect against the SQL injection and web exploit attempts.
  2. Increase the memory of the Lambda functions, Transition to Amazon Redshift for the database. Integrate Amazon Inspector with CloudFront to protect against the SQL injection and web exploit attempts.
  3. Use Lambda functions with provisioned concurrency for compute during peak periods, Transition to Amazon Aurora Serverless for the database. Use CloudFront and subscribe to AWS Shield Advanced to protect against the SQL injection and web exploit attempts.
  4. Use Lambda functions with provisioned concurrency for compute during peak periods. Use RDS Reserved Instances for the database. Integrate AWS WAF with CloudFront to protect against the SQL injection and web exploit attempts. Correct Answer

Community Votes

D
75%
C
25%

75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Each requirement maps to one purpose-built service: provisioned concurrency removes cold starts, Reserved Instances cut cost for predictable steady usage, and WAF attached to CloudFront inspects HTTP requests for injection patterns.

A static S3 site behind CloudFront calls API Gateway and Lambda functions that persist to an Aurora MySQL cluster running On-Demand instances with steady 12-month usage. Peak traffic causes cold starts and slow order processing, and the site is under SQL injection and exploit attempts.

Reaching for AWS Shield Advanced. Shield Advanced provides a subscription-based DDoS protection layer for the distribution but does not inspect request payloads for SQL injection, so it does not address the stated web exploit requirement.

Community Discussion (12 comments)

ebbff63 👍 9 Selected: D
D - AWS WAF for SQL injection and web exploit protection
nimbus_00 👍 1 Selected: D
"DB cluster that uses On-Demand instances. The DB cluster usage has been consistent in the past 12 months." suggests RDS Reserved Instances for the database. https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_WorkingWithReservedDBInstances.html
0b43291 👍 1 Selected: D
By leveraging Lambda functions with provisioned concurrency, RDS Reserved Instances, and AWS WAF with CloudFront, Option D provides a comprehensive solution addressing low-latency access during traffic peaks, optimizing database costs, and adding protection against SQL injection and web exploit attempts, meeting all stated requirements. Option C: While Aurora Serverless addresses database scalability and cost, AWS Shield Advanced may be unnecessary if SQL injection and web exploits are the primary concern, which AWS WAF can mitigate.
JoeTromundo 👍 2 Selected: D
It's D: Provisioned Concurrency ensures that Lambda functions are pre-warmed and ready to handle requests instantly, which reduces the "cold start" problem. RDS Reserved Instances for Amazon RDS will help reduce the database cost. Since the workload has been consistent over the past 12 months, Reserved Instances provide a cost-effective solution by offering significant discounts compared to On-Demand pricing. AWS WAF protects the application from web exploits such as SQL injection and cross-site scripting (XSS).
wbedair 👍 2 Selected: D
waf for sql injection and web exploits
wbedair 👍 1 Selected: C
expanding business needs serverless database so Aurora in option C is the best
Isaac_lin 👍 1
using shield advanced will enable the basic features of WAF for free as well, so C
asquared16 👍 3 Selected: C
Regardless of the diabolical wording of the question. Forget about whether it's WAF or Shield Advance, it's 'C' because it drills down to saying "the company is now expecting growth and needs to ensure scalability", this pushes us to Aurora Serverless. DB usage was consistent last year, it no longer is.
vip2 👍 3 Selected: D
AWS WAF instead of AWS Shield
gfhbox0083 👍 2
D, for sure. To protect against SQL injection attacks, AWS WAF (Web Application Firewall) is the appropriate service to use, not AWS Shield Advanced.
mifune 👍 2 Selected: C
Lambda functions with provisioned concurrency for compute during peak periods + Aurora Serverless + AWS Shield Advanced, I don't see any better choice. Answer C.
zapper1234 👍 1
C - using Lambda concuraancy with Aurora Serverless solves a bunch of the issues

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Provisioned concurrency keeps a set of Lambda execution environments initialized, so order processing no longer waits on cold starts during peaks. Because the database usage has been consistent for twelve months, RDS Reserved Instances convert that predictable baseline into a lower hourly rate with no architectural change. AWS WAF attached to the CloudFront distribution inspects incoming requests at the layer where the static site is served, and its managed rules include SQL injection and known exploit patterns, so malicious requests can be blocked before they reach Lambda. Together the three address compute latency, database cost, and application-layer protection in one set of changes.

Why the Other Options Are Wrong

A: Raising the Lambda timeout does not remove cold starts, so the latency requirement is not addressed at all. B: Amazon Inspector cannot be integrated with CloudFront to protect against SQL injection, and migrating to Redshift is an analytical warehouse rather than an operational transactional store. C: Aurora Serverless is a reasonable serverless option but does not deliver the cost saving of Reserved Instances for steady twelve-month usage, and AWS Shield Advanced is a DDoS protection subscription rather than a payload-inspecting web application firewall, so it does not block SQL injection attempts.

Community Comment Notes

The community voted 75 to 25 for D over C, and the deciding argument was that WAF is the service that inspects requests for SQL injection and web exploits while Shield Advanced focuses on layer 3 and 4 DDoS protection. A commenter also pointed out that the steady twelve-month usage pattern in the question is the explicit signal to choose Reserved Instances over Serverless.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide