AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceEasy
A global e-commerce company uses AWS CloudFront to deliver its web content. To protect against common web exploits and unwanted bot traffic, the security team requires a solution that inspects incoming web requests and blocks malicious traffic before it reaches the origin servers. This solution must be highly available and integrate seamlessly with CloudFront. Which AWS service should the DevOps engineer implement?
- AAmazon Inspector
- BAWS Shield Advanced
- CAWS WAF
- DAWS GuardDuty
Show answer & explanationAnswer & explanation
Correct answer: C. AWS WAF
AWS WAF (Web Application Firewall) helps protect web applications or APIs from common web exploits that may affect availability, compromise security, or consume excessive resources. It can be associated directly with CloudFront distributions to inspect incoming requests and block malicious traffic at the edge.
Why the other options are wrong
- A. Amazon Inspector is a vulnerability management service that scans EC2 instances and container images, not a service for filtering incoming web traffic.
- B. AWS Shield Advanced provides DDoS protection, but not protection against common web exploits like SQL injection or cross-site scripting.
- D. AWS GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, but it's not a web application firewall that blocks requests at the edge.
AWS WAF
A web application firewall that helps protect your web applications or APIs from common web exploits that may affect availability, compromise security, or consume excessive resources.
- Filters web traffic based on rules.
- Protects against SQL injection, XSS, bots, etc.
- Integrates with CloudFront, ALB, API Gateway, AppSync.
Memory trick: WAF is the 'bouncer' for your web app, blocking bad requests at the door.