AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium

A global e-commerce company operates several highly critical web applications behind Application Load Balancers (ALBs). The security team needs to monitor for web-based attacks, such as SQL injection and cross-site scripting (XSS), and block malicious traffic in real-time. They also require detailed logs of blocked requests for forensic analysis. Which AWS security service, combined with its logging capabilities, should be implemented?

  1. AAmazon GuardDuty, with findings sent to CloudWatch Logs.
  2. BAWS WAF, with full logging enabled to an Amazon Kinesis Data Firehose delivery stream.
  3. CVPC Flow Logs, with filtering in CloudWatch Logs Insights.
  4. DAWS Shield Advanced, with event logging to S3.
Show answer & explanation

Correct answer: B. AWS WAF, with full logging enabled to an Amazon Kinesis Data Firehose delivery stream.

AWS WAF (Web Application Firewall) is specifically designed to protect web applications from common web exploits like SQL injection and XSS. It allows defining rules to block malicious traffic. Enabling full logging for WAF to a Kinesis Data Firehose delivery stream provides detailed, near real-time logs of all web requests (including blocked ones), which is essential for forensic analysis.

Why the other options are wrong

  • A. GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, but it does not directly block web-based attacks or provide detailed web request logs like WAF.
  • C. VPC Flow Logs capture network traffic metadata at the IP level, not the detailed HTTP/HTTPS request information needed to identify and block web-based attacks or perform forensic analysis on web exploits.
  • D. AWS Shield Advanced provides DDoS protection at layers 3, 4, and 7, but it is not a web application firewall for detecting and blocking specific web exploits like SQL injection or XSS.

AWS WAF Logging

AWS WAF protects web applications from common exploits, and its logging feature sends detailed web request information to a Kinesis Data Firehose stream for analysis.

  • AWS WAF filters web traffic based on defined rules.
  • Protects against SQL injection, XSS, and other OWASP Top 10 threats.
  • WAF logs provide granular details of every web request.
  • Kinesis Data Firehose is an ideal destination for WAF logs for real-time processing.

Memory trick: WAF blocks web threats, Firehose logs the deeds, for forensic needs.

More Domain 2: Logging and Monitoring questions