AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A media company runs a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. They want to protect the application from common web exploits such as SQL injection and cross-site scripting by inspecting incoming HTTP requests. Which service should they deploy?

  1. AAWS WAF
  2. BAWS Shield Standard
  3. CAmazon Inspector
  4. DAWS Key Management Service
Show answer & explanation

Correct answer: A. AWS WAF

AWS WAF (Web Application Firewall) lets customers create rules to inspect and filter HTTP/HTTPS requests, blocking common exploits like SQL injection and cross-site scripting.

Why the other options are wrong

  • B. Shield Standard protects against DDoS attacks, not application-layer exploits like SQL injection.
  • C. Inspector performs vulnerability scanning of instances and images, not live request filtering.
  • D. KMS manages encryption keys and has no role in filtering web traffic.

AWS WAF

A web application firewall that lets you monitor and control HTTP/HTTPS requests forwarded to protected resources based on customizable rules.

  • Protects against SQL injection, XSS, and other common exploits
  • Can be attached to CloudFront, ALB, API Gateway, and AppSync
  • Uses rules and rule groups (managed or custom)

Memory trick: WAF = Wall Against Forgeries at the web layer.

More Security and Compliance questions