AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceMedium

A global e-commerce company uses AWS CloudFront to deliver its web content. The security team has observed an increase in SQL injection and cross-site scripting (XSS) attacks. They need to implement a solution that can identify and block these common web exploits at the edge, before they reach the origin servers, without modifying the application code. Which AWS service should a DevOps engineer implement?

  1. AAmazon GuardDuty to detect unusual activity and potential threats to AWS accounts.
  2. BAWS Firewall Manager to centrally manage firewall rules across multiple AWS accounts.
  3. CAWS WAF (Web Application Firewall) integrated with CloudFront to filter web requests.
  4. DAWS Shield Advanced to protect against DDoS attacks and block malicious IP addresses.
Show answer & explanation

Correct answer: C. AWS WAF (Web Application Firewall) integrated with CloudFront to filter web requests.

AWS WAF is a web application firewall that helps protect web applications or APIs from common web exploits. It can be integrated directly with CloudFront to filter malicious traffic like SQL injection and XSS at the edge, before it reaches the origin servers.

Why the other options are wrong

  • A. Amazon GuardDuty is a threat detection service for AWS accounts and workloads; it does not directly block web exploits at the application layer.
  • B. AWS Firewall Manager centrally manages WAF rules, but WAF itself is the service that provides the actual protection against web exploits.
  • D. AWS Shield Advanced primarily protects against DDoS attacks; while it has some WAF integration, WAF itself is the direct solution for SQLi/XSS.

AWS WAF for Web Exploits

AWS WAF (Web Application Firewall) protects web applications and APIs from common web exploits like SQL injection and XSS by defining customizable rules to allow, block, or count web requests.

  • Integrates with CloudFront, ALB, API Gateway, AppSync, Cognito.
  • Filters traffic based on IP addresses, HTTP headers, URI strings, etc.
  • Managed rules for common threats are available.

Memory trick: WAF 'guards' the 'web' 'edge' from 'bad' requests.

More Security and Compliance questions