AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A company notices that a single IP address is sending an unusually high volume of HTTP requests per minute to its web application, attempting to overwhelm the login page with credential-stuffing attempts. Which AWS WAF feature should be configured to automatically block this behavior?

  1. AAn IP set match rule
  2. BA rate-based rule
  3. CA SQL injection managed rule group
  4. DA geographic match rule
Show answer & explanation

Correct answer: B. A rate-based rule

A rate-based rule in AWS WAF tracks the request rate from individual IP addresses over a time window and automatically blocks IPs that exceed a defined threshold, which is ideal for mitigating application-layer request floods and credential-stuffing attempts.

Why the other options are wrong

  • A. IP set rules block specific known IPs but don't dynamically respond to request rate.
  • C. SQL injection rules protect against injection attacks, not request flooding.
  • D. Geographic rules filter by country, not by request volume.

WAF Rate-Based Rule

An AWS WAF rate-based rule tracks the number of requests from an IP address over a rolling time window and blocks IPs that exceed a set threshold.

  • Effective against application-layer DDoS/brute-force attempts
  • Threshold is configurable (requests per 5-minute window)
  • Complements Shield, which protects at network/transport layers

Memory trick: Too many knocks, WAF shuts the door

More Security and Compliance questions