AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A global e-commerce company uses Amazon CloudFront to deliver its web application content. They have noticed an increasing number of automated attacks, including SQL injection and cross-site scripting (XSS), targeting their application endpoints. They need a scalable solution that can effectively block these types of attacks without introducing significant latency and that can be integrated directly with CloudFront. Which AWS service should they implement?

  1. AAmazon GuardDuty
  2. BAWS Shield Standard
  3. CAWS WAF
  4. DNetwork Access Control Lists (NACLs)
Show answer & explanation

Correct answer: C. AWS WAF

AWS WAF (Web Application Firewall) is designed to protect web applications or APIs from common web exploits that may affect availability, compromise security, or consume excessive resources. It can filter requests based on SQL injection and XSS patterns and integrates seamlessly with CloudFront to block malicious traffic at the edge.

Why the other options are wrong

  • A. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, but it does not actively block or filter web requests in real-time like WAF.
  • B. AWS Shield Standard provides protection against common DDoS attacks; it does not protect against application-layer attacks like SQL injection or XSS.
  • D. NACLs operate at the subnet level and provide stateless packet filtering; they cannot inspect application-layer content for SQL injection or XSS attacks.

AWS WAF

A web application firewall that helps protect your web applications or APIs from common web exploits that may affect availability, compromise security, or consume excessive resources.

  • Protects against common web exploits like SQL injection and XSS.
  • Integrates with Amazon CloudFront, Application Load Balancer, and API Gateway.
  • Allows creation of custom rules to block or allow traffic.

Memory trick: WAF guards your web apps from common 'W'icked 'A'ttack 'F'ailures.

More Design Secure Architectures questions