AWS Certified Security – SpecialtyDomain 1: Incident ResponseMedium
A company uses AWS WAF to protect its public-facing web applications. A security analyst observes a sudden surge in HTTP 5xx errors and high CPU utilization on backend EC2 instances, coinciding with an increase in requests originating from a single IP address. The analyst suspects a Layer 7 DDoS attack. Which AWS WAF action should be implemented first to mitigate this specific threat?
- AModify the EC2 instance security group to explicitly deny inbound traffic from the suspected malicious IP.
- BConfigure an AWS Shield Advanced protection on the Application Load Balancer (ALB) to absorb the traffic.
- CDeploy Amazon CloudFront in front of the ALB to cache content and absorb traffic spikes.
- DCreate a rate-based rule in AWS WAF to block requests from the originating IP address when the request rate exceeds a threshold.
Show answer & explanationAnswer & explanation
Correct answer: D. Create a rate-based rule in AWS WAF to block requests from the originating IP address when the request rate exceeds a threshold.
A rate-based rule in AWS WAF is specifically designed to mitigate Layer 7 DDoS attacks by automatically blocking or counting requests from IP addresses that exceed a defined request rate within a 5-minute period. This directly addresses the described scenario of a surge from a single IP.
Why the other options are wrong
- A. Modifying security groups manually is reactive, not scalable, and less efficient than an automated WAF rule, especially if the attack source IP changes or expands.
- B. AWS Shield Advanced provides broader DDoS protection but typically involves a more complex setup and is for larger, more sustained attacks. WAF can provide immediate, granular protection at Layer 7.
- C. CloudFront can help absorb traffic and cache content, but it doesn't inherently block malicious Layer 7 requests based on rate. WAF is better suited for this specific type of attack.
AWS WAF Rate-Based Rule
An AWS WAF rule that allows you to specify the number of requests that are allowed from a single IP address within a 5-minute period. If the request rate exceeds the threshold, WAF takes the specified action (e.g., block).
- Mitigates Layer 7 DDoS attacks.
- Blocks IP addresses exceeding a request threshold.
- Operates at the application layer.
Memory trick: WAF's rate rules are your bouncer for web traffic.