AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard

A global e-commerce company needs to secure its web application that uses Amazon EC2 instances behind an Application Load Balancer (ALB). The company must protect against common web exploits like SQL injection and cross-site scripting (XSS) and also needs to restrict access based on IP address blacklists. Which AWS service should be implemented in front of the ALB?

  1. AAWS Network Firewall
  2. BAWS Shield Advanced
  3. CAmazon VPC Security Groups
  4. DAmazon CloudFront with AWS WAF
Show answer & explanation

Correct answer: D. Amazon CloudFront with AWS WAF

Amazon CloudFront, as a CDN, provides global distribution and caching. When integrated with AWS WAF, it can effectively protect against common web exploits (SQL injection, XSS) and allow for IP blacklisting rules at the edge, before traffic reaches the ALB and EC2 instances, providing the most comprehensive solution for a global e-commerce application.

Why the other options are wrong

  • A. AWS Network Firewall operates at the network layer (Layer 3/4) and is designed for VPC traffic filtering, not for protecting against web application layer exploits (Layer 7) like SQL injection or XSS. It's not typically placed in front of an ALB for web application security in this manner.
  • B. AWS Shield Advanced primarily protects against DDoS attacks. While important, it doesn't offer protection against specific web exploits like SQL injection or XSS, nor does it provide IP blacklisting capabilities for web traffic.
  • C. Security Groups operate at the instance/ENI level and provide stateful firewall rules at Layer 4. They can restrict IP ranges but cannot protect against web application layer exploits like SQL injection or XSS.

AWS WAF with CloudFront

AWS WAF (Web Application Firewall) helps protect web applications from common web exploits and unwanted bots. When deployed with CloudFront, it provides edge protection for global applications.

  • WAF protects against common web exploits (SQLi, XSS).
  • WAF can create custom rules (e.g., IP blacklists).
  • CloudFront distributes content globally and integrates WAF at the edge.
  • Provides Layer 7 protection for web applications.

Memory trick: WAF: Web App Firewall

More Design Secure Architectures questions