AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceEasy

A company is deploying a new web application in AWS that processes sensitive customer data. The application requires robust protection against common web exploits such as SQL injection and cross-site scripting (XSS). Additionally, the company wants to implement rate-based rules to mitigate potential DDoS attacks at the application layer. Which AWS service should be used to meet these requirements?

  1. AAWS WAF
  2. BAWS Network Firewall
  3. CAWS Shield Advanced
  4. DAmazon GuardDuty
Show answer & explanation

Correct answer: A. AWS WAF

AWS WAF (Web Application Firewall) is specifically designed to protect web applications or APIs against common web exploits and bots that may affect availability, compromise security, or consume excessive resources. It allows for the creation of custom rules, including rate-based rules, to mitigate application-layer DDoS attacks, directly addressing the stated requirements.

Why the other options are wrong

  • B. AWS Network Firewall provides network-level intrusion prevention and detection for VPC traffic, not specifically for web application exploits.
  • C. AWS Shield Advanced provides enhanced DDoS protection at network and transport layers, but not specific web application exploits like SQL injection or XSS.
  • D. Amazon GuardDuty is a threat detection service that monitors for malicious activity, but it does not provide inline protection for web applications.

AWS WAF

A web application firewall that helps protect your web applications or APIs from common web exploits that may affect availability, compromise security, or consume excessive resources.

  • Protects against SQL injection, XSS, etc.
  • Operates at Layer 7 (application layer).
  • Supports rate-based rules for DDoS mitigation.

Memory trick: WAF guards the 'WEB APP' from 'EXPLOITS'.

More Network Security, Compliance, and Governance questions