What's changed: Deepened ANS-C01 Chapter 6 (SG/NACL eval order/SG references/ephemeral, inspection VPC routing/appliance mode/firewall remits, Shield Adv/WAF Web ACL/Firewall Mgr prereqs/ACM Region + tables, scenarios, FAQ, traps; ja figures)
6.3DDoS Protection and Governance
Attacks and governance—understand Shield Standard/Advanced, WAF, Firewall Manager, certificate management (ACM), and org-wide policy. Apply protection and control across the board.
Handle external attacks with Shield (DDoS) and WAF (L7), and use Firewall Manager to apply policies centrally across many accounts and resources.
6.3.1Protection and central governance
- Shield Standard: automatic and free, mitigating common L3/L4 DDoS at the edge.
- Shield Advanced: paid. Advanced protection for large attacks, SRT support and cost protection.
- WAF: filters HTTP at L7. SQLi/XSS, rate-based rules, IP/geo match.
- Firewall Manager: centrally apply WAF/Shield/SG/Network Firewall policies org-wide for governance.
Common on ANS-C01: L3/L4 DDoS = Shield (large attacks/cost protection = Advanced), L7 SQLi/XSS and rate limiting = WAF, enforce rules org-wide = Firewall Manager, and manage/auto-renew TLS certs = ACM. To enforce the same WAF rules across accounts, use Firewall Manager.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

