A courts case-management review finds the team relies on a WAF alone while application tiers sit in public subnets with broad security groups and unencrypted data stores. Which conclusion is correct?
Select an answer to reveal the explanation.
Short Explanation
One locked front door with all the windows open is not a fortress. WAF helps at the edge, but private subnets, tight security groups, and KMS still have to earn their keep. Stack the layers so a single miss does not dump case files on the sidewalk.
Full Explanation
Reviewing solutions for security at every layer means validating complementary controls rather than a single perimeter product. Typical municipal patterns combine edge protections (WAF/Shield as appropriate), network placement in private subnets, least-privilege security groups, and encryption with KMS for data at rest. Declaring WAF sufficient, exposing data tiers publicly, or dropping security groups undermines defense in depth. Continuous security improvement identifies missing layers and remediates them together.