AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A company notices that a single IP address is sending an unusually high volume of HTTP requests per minute to its web application, attempting to overwhelm the login page with credential-stuffing attempts. Which AWS WAF feature should be configured to automatically block this behavior?
- AAn IP set match rule
- BA rate-based rule
- CA SQL injection managed rule group
- DA geographic match rule
Show answer & explanationAnswer & explanation
Correct answer: B. A rate-based rule
A rate-based rule in AWS WAF tracks the request rate from individual IP addresses over a time window and automatically blocks IPs that exceed a defined threshold, which is ideal for mitigating application-layer request floods and credential-stuffing attempts.
Why the other options are wrong
- A. IP set rules block specific known IPs but don't dynamically respond to request rate.
- C. SQL injection rules protect against injection attacks, not request flooding.
- D. Geographic rules filter by country, not by request volume.
WAF Rate-Based Rule
An AWS WAF rate-based rule tracks the number of requests from an IP address over a rolling time window and blocks IPs that exceed a set threshold.
- Effective against application-layer DDoS/brute-force attempts
- Threshold is configurable (requests per 5-minute window)
- Complements Shield, which protects at network/transport layers
Memory trick: Too many knocks, WAF shuts the door