AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceEasy

A global e-commerce company needs to secure its web application, which is hosted on Amazon EC2 instances behind an Application Load Balancer (ALB). They require protection against common web exploits like SQL injection and cross-site scripting (XSS), and also need to implement rate-based limiting to mitigate DDoS attacks. Which AWS service is best suited to address these requirements?

  1. AAmazon GuardDuty
  2. BAWS Shield Advanced
  3. CAWS WAF
  4. DAWS Network Firewall
Show answer & explanation

Correct answer: C. AWS WAF

AWS WAF (Web Application Firewall) is specifically designed to protect web applications from common web exploits (like SQL injection and XSS) and allows for the creation of custom rules, including rate-based rules, to control bot traffic and mitigate Layer 7 DDoS attacks. It integrates directly with ALBs.

Why the other options are wrong

  • A. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior. It does not provide inline protection against web exploits or active DDoS mitigation.
  • B. AWS Shield Advanced provides enhanced DDoS protection primarily at Layers 3 and 4 (network/transport layer), and some Layer 7 protection, but its core focus is not on common web exploits like SQL injection or XSS.
  • D. AWS Network Firewall provides stateful inspection for VPC traffic at Layers 3-7 but is primarily a network firewall for general traffic, not specifically optimized for web application exploits like WAF.

AWS Web Application Firewall (WAF)

AWS WAF helps protect web applications from common web exploits and bots that may affect availability, compromise security, or consume excessive resources.

  • Protects against SQL injection, XSS, etc.
  • Integrates with CloudFront, ALB, API Gateway, AppSync.
  • Supports custom rules, including rate-based rules for DDoS mitigation.

Memory trick: WAF is the Bouncer for Your Web App's Party.

More Network Security, Compliance, and Governance questions