Build a cost-effective DDoS-resilient architecture with Auto Scaling, ELB, and CloudFront+S3

Answer Correct answer: B — Auto Scaling + ELB + CloudFront with S3 origin leverages free Shield Standard for cost-effective DDoS resilience.

A company is worried about potential DDoS attacks. The company has a web application that runs on Amazon EC2 instances. The application uses Amazon S3 to serve static content such as images and videos. A security engineer must create a resilient architecture that can withstand DDoS attacks. Which solution will meet these requirements MOST cost-effectively?

  1. Create an Amazon CloudWatch alarm that invokes an AWS Lambda function when an EC2 instance’s CPU utilization reaches 90%. Program the Lambda function to update security groups that are attached to the EC2 instance to deny inbound ports 80 and 443.
  2. Put the EC2 instances into an Auto Scaling group behind an Elastic Load Balancing (ELB) load balancer. Use Amazon CioudFront with Amazon S3 as an origin. Correct Answer
  3. Set up a warm standby disaster recovery (DR) environment. Fail over to the warm standby DR environment if a DDoS attack is detected on the application.
  4. Subscribe to AWS Shield Advanced. Configure permissions to allow the Shield Response Team to manage resources on the company's behalf during a DDoS event.

Community Votes

B
65%
D
35%

65% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

AWS Shield Standard is automatically included with CloudFront and Elastic Load Balancing at no cost and provides baseline DDoS protection. Using CloudFront for static content plus an ELB and Auto Scaling group delivers resilience without the $3,000/month Shield Advanced subscription, which is the cost-effective choice when the requirement is general resilience rather than advanced L3/L4/L7 mitigation.

A web app on EC2 serving static content from S3 needs a DDoS-resilient architecture at the lowest cost. Placing the EC2 fleet in an Auto Scaling group behind an ELB absorbs traffic spikes, while serving static assets via Amazon CloudFront (which includes AWS Shield Standard DDoS protection at no extra charge) with S3 as the origin offloads and shields that traffic from the origin.

Defaulting to AWS Shield Advanced for any DDoS concern. It provides stronger protection but costs $3,000/month per organization and is not the most cost-effective option for a standard web app that can be protected by Shield Standard via CloudFront and ELB.

Community Discussion (15 comments)

phmeeeee 👍 1 Selected: B
Shield Advance is not COST-EFFECTIVE DDoS protection solution, for the basic DDOS protection we can use CloudFront for static content with S3 and ALB.
IPLogic 👍 1 Selected: B
To create a resilient architecture that can withstand DDoS attacks in a cost-effective manner, the company should choose Option B: Put the EC2 instances into an Auto Scaling group behind an Elastic Load Balancing (ELB) load balancer. Use Amazon CloudFront with Amazon S3 as an origin. This solution leverages the scalability of Auto Scaling groups and ELB to handle traffic spikes, while Amazon CloudFront provides DDoS protection at the edge, reducing the load on the origin servers. Using S3 as the origin for static content ensures efficient content delivery.
throdrigo 👍 1 Selected: B
The key is the first sentence: “concerned about possible ddos attacks”. So I'll go with B. Cost-Effectiveness Analysis Smaller-Scale or Infrequent DDoS Attacks: Use EC2 with Auto Scaling, ELB, and CloudFront. Frequent or Sophisticated Attacks:AWS Shield Advanced becomes cost-effective
723993f 👍 1 Selected: B
AWS cloudfront includes basic shield, But shield advanced provides cost protection against any infrastructure cost incurred due to ddos Since the company is only “worried” about ddos and it is not actually happening, basic ddos protection included in cloudfront should suffice over shield advanced I would have opted for shield advanced if there were indications of the application being huge or being very critical to the company
mzeynalli 👍 1 Selected: B
NOT D. AWS Shield Advanced: This provides advanced DDoS protection but comes with a significant cost compared to CloudFront's built-in capabilities. AWS Shield Advanced is effective but may not be the most cost-effective solution for a general web application without high sensitivity or stringent uptime requirements. Therefore, Option B provides an architecture that balances both cost and resilience against DDoS attacks effectively.
BietTuot 👍 1 Selected: B
B.javascript:void(0) B is much cheaper than D. Amazon CloudFront is protected by default against DDoS attacks through AWS Shield Standard, which provides automatic protection at no additional cost. This protection includes safeguards against common DDoS attacks on the CloudFront edge network.
golden_fish 👍 1
DDD is the correct
pagom 👍 2 Selected: D
D is the answer. At first glance, it may be B, but if Auto Scaling already reaches its maximum, the service will be paralyzed. However, if you set the maximum number of EC2s to unlimited, your wallet will explode. D is the answer if you want to meet the requirements of the problem at a lower cost.
komik_101 👍 1 Selected: D
DDOS comming+AutoScaling = 1000 ec2 will open :)) cost increases it will be very high. By the way, I did not see the phrase "best cost" in the question. DDOS protection = AWS Shield . I will Go to D.
FunkyFresco 👍 1 Selected: D
Option D makes more sense to me. "Subscribe to AWS Shield Advance".
cumzle_com 👍 2 Selected: B
Option B (Auto Scaling, ELB, CloudFront with S3): The costs can vary widely based on your specific usage patterns (e.g., traffic volume, instance types, storage requirements, etc.). It involves paying for compute resources, load balancing, content delivery, and storage, with costs scaling based on usage. Option D (AWS Shield Advanced): Costs $3,000 per month per organization. This cost provides comprehensive DDoS protection across AWS services, including automated attack detection and mitigation by AWS experts. PLUSSSSSSSSSSSSS Scalability and Performance: Option B provides scalable and performant infrastructure for normal traffic conditions and some level of traffic spikes. It improves availability and latency through caching and load balancing mechanisms. DDoS Protection: Option D (AWS Shield Advanced) is specifically designed for mitigating DDoS attacks, offering proactive protection against large-scale and sophisticated DDoS attacks. It includes access to AWS DDoS Response Team for immediate assistance during attacks.
aescudero51 👍 1 Selected: B
My answer is B Load Balancing: An ELB distributes incoming traffic across multiple EC2 instances, ensuring that no single instance is overwhelmed by traffic. This helps to prevent a single point of failure and reduces the impact of a DDoS attack. Auto Scaling: Auto Scaling ensures that the number of EC2 instances is adjusted based on the load, so if an instance fails or becomes overwhelmed, another instance is launched to replace it. This maintains the availability of the application. CloudFront: Amazon CloudFront acts as a reverse proxy, caching frequently accessed content and reducing the load on the EC2 instances. It also provides a static IP address, which can be used to configure firewall rules and improve security. S3 as Origin: Using S3 as the origin for CloudFront ensures that static content is served efficiently and securely, reducing the load on the EC2 instances and making the application more resilient to DDoS attacks.
DeadDropLabs 👍 2 Selected: B
B - Key is MOST cost effective. Cost-Effective: Using Auto Scaling, ELB, CloudFront, and S3 together is a cost-effective way to manage traffic loads and protect against DDoS attacks. AWS Shield Advanced is an expensive premium service. B will be a cheaper solution.
Cedhulk 👍 2 Selected: D
D for DDOS
mehmetsungur 👍 1
D is the most cost-effective solution for mitigating DDoS attacks and maintaining a resilient architecture.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

CloudFront is protected by AWS Shield Standard by default at no additional cost, and ELB also includes Shield Standard, giving baseline DDoS protection for both the static and dynamic layers. Auto Scaling behind the ELB absorbs volumetric spikes so the origin EC2 fleet is not overwhelmed, and serving images/videos from S3 via CloudFront keeps that traffic off the EC2 instances. This meets the resilience requirement at the lowest cost.

Why the Other Options Are Wrong

A is wrong because a reactive Lambda that denies ports 80/443 on high CPU would take the site offline during an attack, not protect it. C (warm standby DR) adds standing cost and failover complexity without mitigating the attack itself. D (Shield Advanced) is effective but costs $3,000/month and is not the most cost-effective option when Shield Standard via CloudFront/ELB already covers general DDoS resilience.

Community Comment Notes

Community favored B (65 votes). Comments stressed "MOST cost-effective" and that CloudFront includes Shield Standard for free, whereas Shield Advanced is a $3,000/month premium. D supporters worried Auto Scaling could scale to high cost, but the question asks for the most cost-effective design, not unlimited headroom.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide