AWS Certified Security – SpecialtyDomain 1: Incident ResponseMedium

A company uses AWS WAF to protect its public-facing web applications. A security analyst observes a sudden surge in HTTP 5xx errors and high CPU utilization on backend EC2 instances, coinciding with an increase in requests originating from a single IP address. The analyst suspects a Layer 7 DDoS attack. Which AWS WAF action should be implemented first to mitigate this specific threat?

  1. AModify the EC2 instance security group to explicitly deny inbound traffic from the suspected malicious IP.
  2. BConfigure an AWS Shield Advanced protection on the Application Load Balancer (ALB) to absorb the traffic.
  3. CDeploy Amazon CloudFront in front of the ALB to cache content and absorb traffic spikes.
  4. DCreate a rate-based rule in AWS WAF to block requests from the originating IP address when the request rate exceeds a threshold.
Show answer & explanation

Correct answer: D. Create a rate-based rule in AWS WAF to block requests from the originating IP address when the request rate exceeds a threshold.

A rate-based rule in AWS WAF is specifically designed to mitigate Layer 7 DDoS attacks by automatically blocking or counting requests from IP addresses that exceed a defined request rate within a 5-minute period. This directly addresses the described scenario of a surge from a single IP.

Why the other options are wrong

  • A. Modifying security groups manually is reactive, not scalable, and less efficient than an automated WAF rule, especially if the attack source IP changes or expands.
  • B. AWS Shield Advanced provides broader DDoS protection but typically involves a more complex setup and is for larger, more sustained attacks. WAF can provide immediate, granular protection at Layer 7.
  • C. CloudFront can help absorb traffic and cache content, but it doesn't inherently block malicious Layer 7 requests based on rate. WAF is better suited for this specific type of attack.

AWS WAF Rate-Based Rule

An AWS WAF rule that allows you to specify the number of requests that are allowed from a single IP address within a 5-minute period. If the request rate exceeds the threshold, WAF takes the specified action (e.g., block).

  • Mitigates Layer 7 DDoS attacks.
  • Blocks IP addresses exceeding a request threshold.
  • Operates at the application layer.

Memory trick: WAF's rate rules are your bouncer for web traffic.

More Domain 1: Incident Response questions