AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityEasy
A media company is hosting a popular streaming service on AWS, utilizing a fleet of EC2 instances behind an Application Load Balancer (ALB). They observe frequent HTTP flood attacks and malicious bot traffic targeting their web application. The company needs a solution to protect their application from these common web exploits and unwanted traffic, filter requests based on IP addresses and HTTP headers, and integrate seamlessly with their existing ALB. Which AWS service should they implement?
- AAWS Shield Advanced
- BAmazon GuardDuty
- CNetwork Access Control Lists (NACLs)
- DAWS WAF
Show answer & explanationAnswer & explanation
Correct answer: D. AWS WAF
AWS WAF (Web Application Firewall) is designed to protect web applications from common web exploits that could affect application availability or compromise security. It allows filtering requests based on IP addresses, HTTP headers, and other web traffic characteristics, and integrates directly with ALBs.
Why the other options are wrong
- A. AWS Shield Advanced provides enhanced DDoS protection but is not designed for granular web application filtering like HTTP flood attacks or bot traffic based on specific rules.
- B. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, but it does not actively block or filter web traffic.
- C. NACLs operate at the subnet level and are stateless, making them unsuitable for protecting web applications from application-layer attacks like HTTP floods or filtering based on HTTP headers.
AWS Web Application Firewall (WAF)
AWS WAF helps protect web applications or APIs against common web exploits and bots that may affect availability, compromise security, or consume excessive resources.
- Protects against common web exploits (SQL injection, XSS).
- Filters traffic based on custom rules (IPs, HTTP headers).
- Integrates with ALB, CloudFront, API Gateway, AppSync.
- Provides granular control over web requests.
Memory trick: WAF Watches Web Attacks, Shield Stops DDoS.