Prev Next

Cloud / AWS WAF & Shield Interview questions

Last updated

1. What is AWS WAF? 2. What is AWS Shield? 3. What are the two tiers of AWS Shield? 4. What is a web ACL in AWS WAF? 5. What AWS resources can you protect with AWS WAF? 6. What is a rule in AWS WAF? 7. What actions can an AWS WAF rule take? 8. What are AWS Managed Rules? 9. What is a rate-based rule in AWS WAF? 10. What is an IP set in AWS WAF? 11. What is the default action of a web ACL? 12. What are web ACL capacity units (WCUs)? 13. What types of attacks does AWS WAF block? 14. What DDoS attacks does Shield Standard mitigate? 15. What is the AWS Shield Response Team (SRT)? 16. What is DDoS cost protection in Shield Advanced? 17. What is AWS Firewall Manager? 18. What are labels in AWS WAF? 19. How do you enable logging in AWS WAF? 20. List the main match conditions you can use in AWS WAF rules? 21. What is the AWS WAF Bot Control rule group? 22. What is the difference between AWS WAF and AWS Shield? 23. When should you choose Shield Advanced over Shield Standard? 24. How does AWS WAF evaluate rules in a web ACL? 25. Why should you deploy new rules in Count mode first? 26. What is the difference between CloudFront and regional web ACLs? 27. What happens when a request body exceeds the inspection limit? 28. How does a rate-based rule count requests? 29. When should you use a scope-down statement? 30. How does AWS WAF detect SQL injection and XSS? 31. How do you identify the real client IP behind a proxy in AWS WAF? 32. What happens when a web ACL exceeds 1,500 WCUs? 33. How do CAPTCHA and Challenge actions work? 34. How do you redact sensitive fields and filter AWS WAF logs? 35. How does the AWS WAF Anti-DDoS managed rule group work? 36. How do you troubleshoot legitimate requests blocked by AWS WAF? 37. How do you protect an API Gateway REST API with AWS WAF? 38. How can you return a custom response from AWS WAF? 39. How does Account Takeover Prevention work in AWS WAF? 40. How does Account Creation Fraud Prevention work in AWS WAF? 41. How does Shield Advanced application layer automatic mitigation work? 42. How does Shield Advanced proactive engagement work? 43. When can you request DDoS cost protection credits? 44. How do you enable Shield Advanced protection for a resource? 45. How does Firewall Manager enforce AWS WAF policies across accounts? 46. How would you design a DDoS-resilient architecture on AWS? 47. Explain the execution flow of a request through CloudFront, AWS WAF, and Shield? 48. How does managed rule group versioning work in AWS WAF? 49. How can you optimize AWS WAF cost? 50. How do you manage AWS WAF configuration as code?

1. What is AWS WAF?

AWS WAF is a managed web application firewall that filters HTTP and HTTPS requests at Layer 7 before they reach your application. You write rules that look at the IP address, headers, URI, query string, cookies or body, and each rule decides whether to allow, block, count or challenge the request.

It sits in front of CloudFront, Application Load Balancer, API Gateway (REST), AppSync, Cognito user pools, App Runner and Verified Access. Typical uses are blocking SQL injection and cross-site scripting, rate limiting abusive clients, filtering by country and keeping bad bots away.

Pricing is pay-as-you-go: you pay per web ACL, per rule and per million requests inspected. There is no hardware or software to manage.

Take quiz
At which OSI layer does AWS WAF inspect traffic?
Layer 2 (data link layer)
Layer 7 (application layer)
Layer 3 (network layer)
Which of these can AWS WAF inspect to decide on a request?
Only the TCP window size
Only the source MAC address
Headers, URI, query string and body
Only the DNS resolver used

2. What is AWS Shield?

AWS Shield is AWS's managed DDoS (Distributed Denial of Service) protection service. It detects and absorbs floods of malicious traffic aimed at your applications so legitimate users keep getting through.

It comes in two tiers. Shield Standard is on by default for every AWS customer at no extra charge and covers common network and transport layer (L3/L4) attacks. Shield Advanced is a paid subscription that adds L7 protection, attack visibility, 24/7 access to the Shield Response Team and DDoS cost protection.

Shield does not inspect request content the way a firewall does. It focuses on volume and protocol abuse, and it is usually paired with AWS WAF for application-layer rules.

Take quiz
What kind of threat is AWS Shield built to defend against?
SQL injection in form fields
Unpatched operating systems
DDoS attacks
Leaked IAM access keys
Which Shield tier is enabled automatically for all AWS accounts?
Shield Premium
Shield Advanced
Shield Enterprise
Shield Standard

3. What are the two tiers of AWS Shield?

AWS Shield has Shield Standard and Shield Advanced.

Shield Standard Shield Advanced
Cost Free, included for everyone $3,000/month per organization, 1-year commitment, plus data transfer fees
Setup Always on, nothing to enable Subscribe, then add protections per resource
Layers covered L3 and L4 L3, L4 and L7 (with AWS WAF)
Expert help None 24/7 Shield Response Team (needs Business or Enterprise Support)
Cost protection No Credits for DDoS-driven scaling charges

Advanced covers CloudFront, Route 53 hosted zones, Global Accelerator, Elastic Load Balancing and Elastic IPs.

Take quiz
Which Shield tier carries a $3,000 monthly subscription?
Both tiers
Shield Standard
Neither tier
Shield Advanced
Which tier gives you access to the Shield Response Team?
Only AWS WAF customers
Shield Advanced
Shield Standard

4. What is a web ACL in AWS WAF?

A web ACL (web access control list) is the container that holds your AWS WAF rules and rule groups, plus a default action (Allow or Block) for requests that match nothing. You associate it with one or more protected resources, and every request to those resources is evaluated against it.

A resource can have only one web ACL at a time, but one web ACL can protect many resources. A web ACL also has a scope: CLOUDFRONT (global, created in us-east-1) or REGIONAL (tied to a Region). Rules inside it run in priority order, lowest number first.

Newer console screens may label it a protection pack, but the API and most documentation still say web ACL.

Take quiz
How many web ACLs can be associated with a single protected resource at a time?
One
As many as you like
None, rules attach directly to the resource
Up to five
What does a web ACL do with a request that matches no rule?
Forwards it to AWS Shield for review
Applies its default action
Drops it silently with no log
Sends it to the Shield Response Team

5. What AWS resources can you protect with AWS WAF?

AWS WAF attaches to a specific set of front-door services rather than to arbitrary compute:

  • Amazon CloudFront distributions
  • Application Load Balancers
  • Amazon API Gateway REST APIs (at the stage level)
  • AWS AppSync GraphQL APIs
  • Amazon Cognito user pools
  • AWS App Runner services
  • AWS Verified Access instances
  • Amazon Bedrock AgentCore Gateway

Network Load Balancers, EC2 instances and API Gateway HTTP APIs cannot take a web ACL directly. The usual workaround is putting CloudFront or an ALB in front of them.

Take quiz
Which of these cannot have an AWS WAF web ACL attached directly?
Application Load Balancer
Network Load Balancer
AppSync GraphQL API
CloudFront distribution
You need WAF in front of an EC2 web server. What is the common approach?
Put an ALB or CloudFront in front and attach the web ACL there
Install the web ACL as an agent on the instance
Attach the web ACL to the security group

6. What is a rule in AWS WAF?

A rule tells AWS WAF what to look for and what to do when it finds it. It has a name, a priority, a statement (the match logic), an action and a visibility configuration for CloudWatch metrics and sampled requests.

Statements can be simple, like an IP set match, or nested with AND, OR and NOT to build conditions such as 'URI starts with /admin AND country is not US'. Rules you reuse can be grouped into a rule group, and AWS or Marketplace sellers publish managed rule groups you can drop in.

{
  "Name": "BlockAdminFromOutside",
  "Priority": 10,
  "Statement": { "ByteMatchStatement": { "SearchString": "/admin", "FieldToMatch": { "UriPath": {} },
    "TextTransformations": [{ "Priority": 0, "Type": "NONE" }], "PositionalConstraint": "STARTS_WITH" } },
  "Action": { "Block": {} },
  "VisibilityConfig": { "SampledRequestsEnabled": true, "CloudWatchMetricsEnabled": true, "MetricName": "BlockAdmin" }
}

Take quiz
Which element of a rule defines what the rule matches on?
The default action
The log destination
The statement
The scope
How can you combine several conditions inside one rule?
Chain them with Lambda functions
Nest statements with AND, OR and NOT
You cannot, one condition per rule only

7. What actions can an AWS WAF rule take?

A rule can take one of five actions:

Action What happens
Allow Request is passed on, rule evaluation stops. Can add custom request headers.
Block Request is rejected, evaluation stops. Default 403, or a custom response.
Count Request is only counted and logged, evaluation continues.
CAPTCHA Serves a puzzle unless the client holds a valid, unexpired token.
Challenge Runs a silent browser check unless the client holds a valid token.

Allow and Block are terminating. Count is non-terminating, which is why it is the safe way to test a new rule before enforcing it.

Take quiz
Which action lets a request through while evaluation continues to later rules?
CAPTCHA
Allow
Block
Count
Which action runs a silent browser check without showing a puzzle?
Challenge
CAPTCHA
Count
Allow

8. What are AWS Managed Rules?

AWS Managed Rules are rule groups written and updated by AWS security teams, so you get tested protections without authoring regexes yourself. You add a rule group to your web ACL as one reference and AWS maintains the rules behind it.

The baseline groups include the Core rule set (OWASP-style protections), Admin protection and Known bad inputs. Use-case groups cover SQL database, Linux, POSIX, PHP and Windows exploits. IP reputation groups cover Amazon IP reputation and Anonymous IP lists.

Intelligent threat groups, such as Bot Control, Account Takeover Prevention, Account Creation Fraud Prevention and Anti-DDoS, are paid add-ons with extra fees. Third-party sellers also offer managed groups on AWS Marketplace.

Take quiz
Who maintains the rules inside an AWS Managed Rules group?
AWS
You, through scheduled Lambda jobs
Your CloudFront distribution
The Shield Response Team on request only
Which of these is an AWS Managed Rules group aimed at login abuse?
Core rule set
Account Takeover Prevention
Admin protection
Amazon IP reputation list

9. What is a rate-based rule in AWS WAF?

A rate-based rule counts requests from each client over a time window and takes action once a client crosses your limit. It is the standard answer to HTTP floods, brute-force logins and scrapers.

By default it groups requests by source IP. You set a limit (minimum 10) and the window, then choose Block, Count, CAPTCHA or Challenge. When the client's rate drops back under the limit, the action stops being applied automatically.

A single rate-based rule can track up to 10,000 distinct IPs being rate limited at once, and a web ACL can hold up to 10 of them.

Take quiz
What is a rate-based rule mainly used to stop?
Unencrypted HTTP traffic
Request floods and brute-force attempts
Cross-region replication lag
Expired TLS certificates
When a blocked client's request rate falls below the limit, what happens?
The web ACL is deleted
The rule stops applying its action to that client
The client stays blocked until you edit the rule

10. What is an IP set in AWS WAF?

An IP set is a reusable list of IPv4 or IPv6 addresses in CIDR notation that rules can reference. Instead of writing hundreds of addresses into a rule, you keep them in the set and point a rule at it with an IP set reference statement.

Each set holds up to 10,000 addresses, and you can update it without touching the rule. That makes it a good fit for office allow lists, partner ranges and block lists fed by a threat feed.

An IP set match is also one of the cheapest conditions in WCU terms, so it is worth using before heavier regex rules.

Take quiz
What format are addresses stored in inside an IP set?
Hostnames only
MAC addresses
CIDR notation
ASN numbers only
What is the main benefit of an IP set over inline IPs in a rule?
It removes the need for logging
It bypasses the web ACL default action
You can update the list without editing the rule

11. What is the default action of a web ACL?

The default action is what the web ACL does with a request that matches no rule with a terminating action. You must pick either Allow or Block when you create the web ACL.

Most public websites use Allow as the default and add Block rules for known bad traffic. Internal or partner-only APIs often flip it: default Block, plus explicit Allow rules for approved IP ranges or headers.

Like rule actions, the default action can carry custom response codes and headers, so a blocked client can get a friendly 403 page instead of the stock message.

Take quiz
When is the web ACL default action applied?
Only when AWS Shield is subscribed
Before any rule is evaluated
When no rule with a terminating action matches
A partner-only API should reject everyone except approved IPs. Which default action fits?
Block, with Allow rules for the approved IPs
CAPTCHA for everyone
Count, with no other rules
Allow, with no other rules

12. What are web ACL capacity units (WCUs)?

WCUs are a measure of how much processing power your rules need. Each rule costs a number of units based on its complexity: an IP set match costs 1, while a regex pattern set match costs 25.

A rule group's capacity is fixed when you create it and cannot be changed later, so you have to size it up front. A rule group can use up to 5,000 WCUs, and so can a web ACL.

The base web ACL price includes 1,500 WCUs. Going past that adds a per-request fee in tiers, so WCUs affect both design limits and your bill. They do not change how deeply AWS WAF inspects traffic.

Take quiz
How many WCUs are included in the base web ACL price?
1,500
5,000
10,000
500
What is true about a rule group's capacity?
It grows automatically with traffic
It is fixed at creation and cannot be changed later
It resets every month

13. What types of attacks does AWS WAF block?

AWS WAF works on web traffic, so it targets application-layer threats:

  • Injection attacks - SQL injection and command injection patterns in query strings, headers or bodies
  • Cross-site scripting (XSS) - script payloads in request fields
  • Known exploit patterns - for example Log4j-style payloads and path traversal
  • HTTP floods - via rate-based rules and the Anti-DDoS rule group
  • Bots and scrapers - through Bot Control and CAPTCHA or Challenge
  • Credential abuse - stuffing and fake sign-ups via ATP and ACFP
  • Unwanted sources - by country, ASN, or IP reputation

It does not stop volumetric network floods such as SYN or UDP floods. That is Shield's job.

Take quiz
Which attack is AWS WAF designed to block?
Physical theft of a server
SQL injection in a request parameter
UDP reflection attack
SYN flood on the network layer
Which service handles volumetric network-layer floods?
AWS Config
Amazon Inspector
AWS Shield
AWS WAF

14. What DDoS attacks does Shield Standard mitigate?

Shield Standard defends against the most common infrastructure-layer (L3 and L4) DDoS attacks, using always-on detection and inline mitigation in the AWS network.

  • SYN and ACK floods that exhaust connection tables
  • UDP floods
  • Reflection and amplification attacks such as DNS or NTP reflection

It needs no configuration and costs nothing. It gives the strongest protection when your app is behind CloudFront and Route 53, because attack traffic is absorbed at the edge. It does not cover Layer 7 floods, which need WAF rules or Shield Advanced.

Take quiz
Which attack does Shield Standard mitigate?
Credential stuffing
Cross-site scripting
SYN flood
SQL injection
Do you have to enable Shield Standard?
No, it is always on
Yes, per resource through the console
Yes, by buying a subscription

15. What is the AWS Shield Response Team (SRT)?

The Shield Response Team (SRT) is a group of AWS DDoS specialists you can call on during an attack if you subscribe to Shield Advanced and have a Business or Enterprise Support plan. You open a case and they help triage, analyze traffic and suggest mitigations.

If you grant them access, the SRT can write or adjust AWS WAF rules in your account on your behalf during an event. You give that permission through a dedicated IAM role, and optionally let them read your WAF logs in S3.

The team used to be called the DDoS Response Team (DRT), and you may still see that name in older docs and API calls.

Take quiz
What does the SRT need from you before it can edit WAF rules in your account?
An IAM role granting it access
A VPN tunnel into your VPC
Your root account password
What was the Shield Response Team formerly called?
Shield Rapid Operations
DDoS Response Team (DRT)
Cyber Defense Unit

16. What is DDoS cost protection in Shield Advanced?

DDoS cost protection is a Shield Advanced benefit that lets you request AWS service credits for usage spikes caused by a DDoS attack. If your protected resources scale out under attack, you are not stuck paying for that surge.

It covers scaling charges on protected Amazon EC2, Elastic Load Balancing, CloudFront, Global Accelerator and Route 53 resources. You file the request through the normal AWS Support channel after the event.

It is a credit for scaling cost, not a refund of the Shield subscription itself.

Take quiz
What does DDoS cost protection compensate for?
Scaling charges triggered by an attack
Developer salaries during the incident
The $3,000 monthly Shield fee
Lost revenue from downtime
How do you request the credits?
Automatically on your next invoice with no request
By emailing the Route 53 team
Through AWS Support

17. What is AWS Firewall Manager?

AWS Firewall Manager lets a central security team define firewall policies once and enforce them across every account in an AWS Organization. Instead of configuring AWS WAF in 40 accounts by hand, you create one policy and Firewall Manager applies it.

It manages AWS WAF, Shield Advanced, VPC security groups, Network Firewall, Route 53 Resolver DNS Firewall and more. Policies are scoped by account, organizational unit, resource type or tag, and new resources that match the scope are covered automatically.

It requires AWS Organizations, a designated Firewall Manager administrator account, and AWS Config enabled in the member accounts.

Take quiz
What is the main purpose of Firewall Manager?
Replace CloudTrail
Centrally enforce firewall policies across accounts
Run penetration tests
Store TLS certificates
Which service must be in place to use Firewall Manager?
AWS Direct Connect
Amazon Macie
AWS Organizations
Amazon Athena

18. What are labels in AWS WAF?

Labels are tags that a rule attaches to a request while it is being evaluated. A later rule in the same web ACL can match on that label, which lets you split detection from decision.

Managed rule groups use labels heavily. For example, Bot Control labels a request as a verified bot or a scraper, and you can write your own rule that allows one label and rate limits another instead of accepting the group's built-in action.

Labels exist only for that request inside that web ACL. They are not sent to your origin, but they do show up in WAF logs and CloudWatch metrics. A rule can only read labels added by rules with a lower priority number, because those run first.

Take quiz
A rule can match on a label set by another rule only if that other rule:
Uses the Block action
Lives in a different AWS account
Runs earlier, with a lower priority number
Runs later, with a higher priority number
Where are WAF labels visible after evaluation?
In the Route 53 query log
In WAF logs and CloudWatch metrics
Only inside the origin application's headers by default

19. How do you enable logging in AWS WAF?

Logging is enabled per web ACL, not account-wide. You pick one destination and AWS WAF writes a JSON record for each inspected request.

Destination Good for
CloudWatch Logs log group Quick searches with Logs Insights and alarms
S3 bucket Cheap long-term storage and Athena queries
Data Firehose stream Streaming to Splunk, OpenSearch or another SIEM

The destination name must start with aws-waf-logs-. In the console, open the web ACL, go to Logging and metrics, enable logging and choose the destination. Each record includes the action, the terminating rule, matched labels and full request details such as headers and URI.

Take quiz
What prefix must a WAF logging destination name start with?
aws-shield-
cloudtrail-waf-
waf-audit-
aws-waf-logs-
At what level is WAF logging enabled?
Per Region for the whole account
Per IP set
Per web ACL
Which destination suits streaming logs into a third-party SIEM?
Data Firehose
AWS Config rules
IAM Access Analyzer

20. List the main match conditions you can use in AWS WAF rules?

AWS WAF statements can match on many parts of a request:

  • IP address - single IP, CIDR range or IP set
  • Geo match - by country, plus ASN match for network owner
  • String match - contains, starts with, ends with, exactly, or regex
  • SQLi and XSS match - built-in detection on a chosen field
  • Size constraint - length of body, header, query string or URI
  • Label match - react to labels set by earlier rules
  • Rate-based - count requests per key over a window
  • Rule group reference - your own or managed rule groups

The part of the request to inspect (URI path, query string, a named header, cookies, JSON body, method) is chosen with a 'field to match', and text transformations such as URL decoding can be applied first. Any of these can be combined with AND, OR and NOT.

Take quiz
Which statement type reacts to metadata added by an earlier rule?
Label match
Geo match
IP set reference
Size constraint
What do text transformations do?
Normalize the input, for example URL-decode it, before matching
Translate the request into another language
Encrypt the request body

21. What is the AWS WAF Bot Control rule group?

Bot Control (AWSManagedRulesBotControlRuleSet) is a paid managed rule group that detects and manages automated traffic. It comes in two inspection levels.

  • Common - identifies self-declared bots by user agent and verifies well-known ones, such as search engines, through reverse DNS
  • Targeted - goes after evasive bots using browser interrogation, fingerprinting and behavior analysis, and relies on CAPTCHA or Challenge tokens

Instead of blocking everything, it mostly labels traffic by category (verified bot, scraper, HTTP library and so on). You then decide per label: allow search engines, count monitoring tools, block scrapers. Because it adds per-request fees, scope it down to the paths that matter.

Take quiz
What does the Common level of Bot Control mainly identify?
Self-identifying bots and verified bots
SQL injection payloads
Only credential-stuffing tools
What is the recommended way to control Bot Control's cost?
Run it on every request in the web ACL with no limits
Use a scope-down statement to limit what it inspects
Disable logging

22. What is the difference between AWS WAF and AWS Shield?

They solve different problems and are meant to be used together. WAF looks at what a request says; Shield looks at how much traffic is arriving and whether it abuses the network protocol.

AWS WAF AWS Shield
Protects against Injection, XSS, bots, request floods, unwanted sources DDoS attacks
Layer Layer 7 (HTTP/HTTPS) L3/L4 (Standard), L3/L4/L7 (Advanced)
You configure Web ACLs, rules, rule groups Nothing (Standard), protections and health checks (Advanced)
Pricing Per web ACL, rule and request Free (Standard), $3,000/month (Advanced)
Attached to CloudFront, ALB, API Gateway and others CloudFront, Route 53, Global Accelerator, ELB, Elastic IP

A SQL injection attempt is a WAF problem. A 500 Gbps UDP flood is a Shield problem. An HTTP flood is where the two overlap, and Shield Advanced uses WAF rules to mitigate it.

Take quiz
Which service would block a SQL injection attempt in a query string?
AWS KMS
AWS Shield Standard
AWS WAF
Amazon Route 53
Which of these needs no configuration at all?
AWS WAF web ACLs
Firewall Manager policies
Shield Advanced protections
Shield Standard

23. When should you choose Shield Advanced over Shield Standard?

Stay on Standard if an outage from a DDoS would be annoying but not costly. Move to Advanced when downtime or surprise bills would hurt. Typical triggers:

  • Revenue-critical sites such as e-commerce, gaming, fintech or media streaming
  • You have been targeted before, or expect extortion-style (ransom DDoS) attempts
  • You need L7 DDoS detection and mitigation without building it all yourself
  • You want the Shield Response Team on call and proactive engagement
  • Your workload autoscales heavily and a flood could generate a large bill
  • Compliance or customers expect documented DDoS protections

The $3,000 monthly fee covers the whole organization, so it is easier to justify when many accounts share it. Remember that SRT access also requires a Business or Enterprise Support plan, which is an extra cost to plan for.

Take quiz
Which situation best justifies Shield Advanced?
A dev sandbox that is rarely used
A static personal blog with no revenue
A revenue-critical app that autoscales and has been targeted before
What else is required to reach the Shield Response Team?
A Business or Enterprise Support plan
A Route 53 private hosted zone
A dedicated Direct Connect link

24. How does AWS WAF evaluate rules in a web ACL?

AWS WAF checks rules in ascending priority order: the lowest number runs first. As soon as a rule with a terminating action (Allow or Block) matches, evaluation stops and that action is applied.

Non-terminating actions such as Count do not stop the flow. The request moves on to the next rule, and any labels or counts are recorded along the way. If it passes every rule without a terminating match, the web ACL default action decides its fate.

flowchart TD
  A["Request arrives"] --> B{Next rule by priority}
  B -->|Match + Allow or Block| C["Apply action and stop"]
  B -->|Match + Count| D["Count and label"]
  D --> B
  B -->|No match| B
  B -->|No rules left| E["Apply default action"]

This is why order matters. Put a cheap Allow for trusted IPs near the top and block rules before expensive inspection.

Take quiz
What happens once a rule with a Block action matches?
Evaluation stops and the request is blocked
The request is sent to the default action
The rest of the rules still run and may override it
In which order does AWS WAF evaluate rules?
Random order each time
Lowest priority number first
Highest priority number first
Alphabetically by rule name

25. Why should you deploy new rules in Count mode first?

Count mode lets a rule match and be logged without affecting the request, so you can see what it would have blocked before it blocks anything real. New rules, especially regex and managed groups, can catch legitimate traffic you did not think of.

  1. Add the rule with the action set to Count (or override a managed rule's action to Count)
  2. Watch CloudWatch metrics, sampled requests and WAF logs for a few days across peak traffic
  3. Check whether matches are real attacks or valid users, such as large form posts or API clients
  4. Tune or scope the rule, then switch to Block

Count also still adds labels, so you can build label-based logic while the rule is in observation. Skipping this step is a common reason a new rule causes an outage on release day.

Take quiz
What does Count mode do when a rule matches?
Blocks the request and logs it
Records the match and lets evaluation continue
Deletes the rule automatically
What is the main reason to start in Count mode?
To disable CloudWatch metrics
To reduce the web ACL price
To find false positives before enforcing

26. What is the difference between CloudFront and regional web ACLs?

A web ACL has one of two scopes, chosen at creation, and it cannot be changed afterwards.

CLOUDFRONT scope REGIONAL scope
Protects CloudFront distributions ALB, API Gateway, AppSync, Cognito, App Runner, Verified Access
Where it lives Global, managed in US East (N. Virginia) us-east-1 In the same Region as the resource
Where traffic is filtered At CloudFront edge locations In the Region, at the resource
Body inspection default 16 KB, up to 64 KB ALB and AppSync fixed at 8 KB; others 16 KB default

Rule groups, IP sets and regex sets also have a scope and cannot be shared across scopes. To cover both a CloudFront distribution and an ALB, you need two web ACLs, and Firewall Manager can keep them in sync.

Take quiz
Where must a CloudFront-scope web ACL be created?
In the Region closest to the origin
eu-west-1 only
US East (N. Virginia), us-east-1
In any Region you like
Can an IP set created with CLOUDFRONT scope be used in a regional web ACL?
No, scopes cannot be mixed
Yes, always
Yes, if you enable cross-scope sharing

27. What happens when a request body exceeds the inspection limit?

AWS WAF only inspects the first part of a body. For ALB and AppSync that limit is a fixed 8 KB. For CloudFront, API Gateway, Cognito, App Runner and Verified Access it is 16 KB by default and can be raised up to 64 KB (extra fee per additional 16 KB).

What WAF does next is set per rule through oversize handling:

  • CONTINUE - inspect the portion available and judge on that
  • MATCH - treat the oversized request as a match
  • NO_MATCH - treat it as not matching

This is a real bypass route. An attacker can pad a payload with junk so the malicious part sits beyond the limit. The fix is a size constraint rule that blocks bodies over the limit on endpoints that never need big payloads, and a separate allowance for upload paths. Headers and cookies have similar limits (first 8 KB or 200 items).

Take quiz
How can an attacker abuse the body inspection limit?
Pad the request so the payload falls past the inspected portion
Send the request over IPv6
Use a longer domain name
What is the fixed body inspection limit for an Application Load Balancer?
8 KB
1 MB
64 KB
There is no limit

28. How does a rate-based rule count requests?

A rate-based rule keeps a running count per aggregation key over a sliding time window and acts once that count passes your limit.

  • Window - 1, 2, 5 or 10 minutes (5 is the default)
  • Limit - the request threshold per key, minimum 10
  • Key - source IP by default, or forwarded IP, header, cookie, query argument, URI path, HTTP method, label namespace, JA3 or JA4 fingerprint, and combinations of these
  • Scope-down - an optional statement to count only a subset, such as POST /login

Custom keys are what make it useful beyond plain IP limits. For example, you can cap each API key or each session cookie separately, so a shared corporate NAT address does not lock out a whole office. Enforcement is not instant; expect a short delay between crossing the threshold and the action starting.

Take quiz
What is the default aggregation key of a rate-based rule?
Source IP address
Request body hash
AWS account ID
Hostname of the origin
Why use a custom aggregation key such as an API key header?
To bypass the window setting
To disable the rate limit
To limit each caller separately instead of lumping users behind one IP

29. When should you use a scope-down statement?

A scope-down statement narrows which requests a rule or managed rule group looks at. You use it when only part of your traffic needs the check, which makes rules both more accurate and cheaper.

  • Rate limit only /login or /api/search instead of the whole site
  • Run Bot Control, ATP or ACFP only on sensitive paths, since they charge per inspected request
  • Skip inspection for a known-safe path that keeps triggering a managed rule
  • Apply a rule only to a specific host header in a shared web ACL
"ScopeDownStatement": {
  "ByteMatchStatement": {
    "SearchString": "/login",
    "FieldToMatch": { "UriPath": {} },
    "TextTransformations": [{ "Priority": 0, "Type": "NONE" }],
    "PositionalConstraint": "STARTS_WITH"
  }
}

One exception: AWS recommends against scope-down on the Anti-DDoS rule group, since it needs to see all traffic.

Take quiz
Why would you scope down Bot Control to the checkout path?
To turn off labels
To make it block all other paths
To reduce per-request inspection fees and focus on sensitive traffic
Which managed rule group should generally NOT use a scope-down statement?
Anti-DDoS
Bot Control
Account Takeover Prevention

30. How does AWS WAF detect SQL injection and XSS?

AWS WAF has built-in SQLi and XSS match statements. You pick which part of the request to inspect (query string, body, a header, cookies) and the engine looks for attack syntax rather than a fixed string.

Text transformations make the check harder to evade. URL decoding, HTML entity decoding and lowercase conversion run first, so an encoded payload like %27%20OR%201%3D1 is normalized before matching. The SQLi statement also has a sensitivity level, LOW or HIGH; HIGH catches more but can raise false positives.

You can skip writing these yourself by using the AWS Managed Rules SQL database group and the Core rule set. Remember that WAF is a safety net. The real fix is parameterized queries and output encoding in the application.

Take quiz
Why apply URL decoding as a text transformation before an SQLi check?
So encoded payloads are normalized before matching
To compress the request body
To hide the request from CloudWatch
What is the trade-off of a HIGH SQLi sensitivity level?
It only inspects the URI
Catches more attacks but may flag legitimate requests
Faster responses with lower accuracy

31. How do you identify the real client IP behind a proxy in AWS WAF?

If CloudFront or another proxy sits in front of your ALB, the ALB-level web ACL sees the proxy's address as the source. IP rules, geo match and rate limits would then hit the wrong address.

The fix is the forwarded IP configuration. You tell the rule to read the client address from a header, usually X-Forwarded-For, and choose which entry to use (first, last or any). You also set a fallback behavior, MATCH or NO_MATCH, for requests where the header is missing or malformed.

This works for IP set match, geo match and rate-based rules. Keep in mind that clients can forge X-Forwarded-For, so trust it only when a proxy you control sets it. Attaching the web ACL at CloudFront, the true edge, avoids the problem.

Take quiz
Why might an ALB web ACL see the wrong source IP?
IPv6 hides all addresses
A proxy such as CloudFront sits in front and its IP is the source
WAF always masks client IPs
What does the fallback behavior in forwarded IP config control?
Which Region the logs go to
The size of the IP set
How to treat requests with a missing or invalid header

32. What happens when a web ACL exceeds 1,500 WCUs?

Nothing breaks. A web ACL can use up to 5,000 WCUs, and the 1,500 mark is simply where the base price stops. Beyond it, AWS WAF adds a request charge in tiers, currently $0.20 per million requests for each additional 500 WCUs used.

The hard limit is 5,000. Past that, you cannot add rules, and a rule group's own capacity cannot exceed 5,000 either. Since rule group capacity is permanent, you have to rebuild the group to change it.

Ways to stay under the line: replace many IP rules with one IP set, avoid regex pattern sets (25 WCUs each), drop duplicate or overlapping rules, and check the capacity of each managed group before adding it.

Take quiz
What is the maximum WCU capacity of a web ACL?
5,000
2,500
Unlimited
1,500
Which change would lower your WCU usage?
Merging many IP rules into a single IP set
Duplicating rules for redundancy
Adding more regex pattern sets

33. How do CAPTCHA and Challenge actions work?

Both actions check whether the client holds a valid AWS WAF token. If it does, the request passes. If not, WAF blocks the request and sends a check instead.

CAPTCHA Challenge
What the user sees A puzzle to solve Nothing, runs silently in the browser
Best for Suspicious traffic where a human can reasonably help Filtering simple bots with zero friction

Once the client solves the check, it gets a token stored as a cookie, and the immunity time (default 300 seconds) decides how long the token is trusted before another check. These actions work for normal browser page loads. For fetch or XHR calls, mobile apps or single-page apps, you integrate the AWS WAF JavaScript or mobile SDK so the client can fetch and attach tokens itself.

Take quiz
What is the main difference between CAPTCHA and Challenge?
CAPTCHA shows a puzzle; Challenge runs silently
CAPTCHA needs Shield Advanced; Challenge does not
Challenge always blocks; CAPTCHA always allows
What does immunity time control?
The size of the request body inspected
How long a valid token is trusted before re-checking
The rate limit window

34. How do you redact sensitive fields and filter AWS WAF logs?

Raw WAF logs can hold tokens, passwords in query strings or cookies you would rather not store. Two logging settings handle that:

  • Redacted fields - choose request parts to mask in the logs: URI path, query string, a named header, the HTTP method, or the body (JSON body fields). The value is replaced, but the rest of the record stays intact.
  • Logging filter - keep or drop records by condition, for example keep only Block and Count, or only requests carrying a specific label.

Filtering matters for cost. Logging every allowed request on a busy site can dwarf your WAF bill in S3 or CloudWatch Logs ingestion. A common pattern is to log blocked and counted requests plus a labeled sample of allowed ones, then use Athena over S3 for investigations.

Take quiz
What does a redacted field do in WAF logs?
Deletes the web ACL
Masks that part of the request in the log record
Blocks requests containing the field
Why use a logging filter?
To speed up rule evaluation
To enable CAPTCHA
To keep only the records you need and control log costs

35. How does the AWS WAF Anti-DDoS managed rule group work?

The Anti-DDoS managed rule group (AWSManagedRulesAntiDDoSRuleSet) watches traffic to the web ACL, learns what normal looks like, and detects HTTP request floods. It labels requests, marks the likely attackers by suspicion level and then challenges or blocks them.

  • Every inspected request gets labels such as event-detected and low, medium or high suspicion
  • Challenge can run silently in the browser, and you can exempt non-HTML paths such as APIs
  • Sensitivity (Low, Medium, High) is set separately for Block and Challenge
  • It needs 50 WCUs and no Route 53 health checks

Place it at the highest priority, or right under custom Allow rules, so it sees as much traffic as possible. Any customer can use it for an added fee, and Shield Advanced subscribers get it included. During active mitigation, blocked attack requests are excluded from request charges.

Take quiz
Where should the Anti-DDoS managed rule group sit in the web ACL?
After all other rules
In a separate account
At the highest priority, below any custom Allow rules
What labels does it add to requests?
Suspicion-level labels such as high-suspicion-ddos-request
A copy of the request body
Only the client's country

36. How do you troubleshoot legitimate requests blocked by AWS WAF?

Start with evidence from the logs, not guesses. Each blocked record names the rule that stopped the request.

  1. Ask for the time, URL and client IP, or a request ID from the 403 page
  2. Find the entry in WAF logs or sampled requests and read terminatingRuleId and ruleGroupList to see which rule fired
  3. If it came from a managed group, note the exact sub-rule, for example a body size or XSS rule
  4. Switch only that sub-rule to Count with a rule action override
  5. Add a narrow exception: a scope-down or a label-based Allow for that path, not a blanket Allow
  6. Re-test and monitor the Count metrics before turning it back to Block
fields @timestamp, httpRequest.clientIp, httpRequest.uri, terminatingRuleId, action
| filter action = 'BLOCK' and httpRequest.uri like /checkout/
| sort @timestamp desc
| limit 50

Avoid disabling the whole rule group. That removes protection for every other path.

Take quiz
Which log field tells you which rule blocked a request?
terminatingRuleId
httpVersion
httpRequest.clientIp
timestamp
What is the safest way to fix a false positive from one managed sub-rule?
Disable the entire managed rule group
Override that sub-rule to Count and add a narrow exception
Delete the whole web ACL

37. How do you protect an API Gateway REST API with AWS WAF?

Create a regional web ACL in the same Region as the API, then associate it with the API's stage. WAF runs before the request reaches your integration, so blocked calls never invoke a Lambda or backend.

aws wafv2 associate-web-acl \
  --web-acl-arn arn:aws:wafv2:us-east-1:111122223333:regional/webacl/api-acl/abcd1234 \
  --resource-arn arn:aws:apigateway:us-east-1::/restapis/a1b2c3/stages/prod

Association is per stage, so dev and prod can have different web ACLs. Only REST APIs are supported. HTTP APIs and WebSocket APIs cannot take a web ACL directly, so place CloudFront in front of them.

Useful rules for APIs: a rate-based rule keyed on the API key or Authorization header, the Core rule set and Known bad inputs groups, and an IP allow list for partner-only endpoints. WAF complements API Gateway throttling and usage plans, it does not replace them.

Take quiz
At what level is a web ACL associated with an API Gateway REST API?
The account
The stage
The VPC
Each individual Lambda function
Which API Gateway API type can have a web ACL associated with its stage?
WebSocket API
HTTP API
REST API

38. How can you return a custom response from AWS WAF?

A Block action can return your own status code, headers and body instead of the default 403. This is handy for a branded error page, a 429 on rate limiting, or a JSON error for API clients.

  1. Define a custom response body at the web ACL level with a key, content type (text, JSON or HTML) and content
  2. In the rule's Block action, enable custom response and set the status code and any headers
  3. Reference the body by its key

The combined size of all custom response bodies in a web ACL or rule group is capped at 50 KB.

Other actions can add things too. Allow, Count, CAPTCHA and Challenge can insert custom request headers. WAF prefixes them with x-amzn-waf-, so your origin can see a tag such as which rule matched and handle that traffic differently.

Take quiz
What prefix does AWS WAF add to custom request headers it inserts?
x-shield-
x-forwarded-
x-amzn-waf-
x-aws-block-
Which action can return a custom status code and body?
Count
None, the response is fixed
Allow only
Block

39. How does Account Takeover Prevention work in AWS WAF?

Account Takeover Prevention (ATP) is a managed rule group (AWSManagedRulesATPRuleSet) that protects login endpoints from stolen credential use, credential stuffing and brute force.

You tell it your login path and how credentials are sent (field names for username and password, JSON or form encoded). ATP then does three things:

  • Checks submitted credentials against a database of known-compromised credentials
  • Tracks volumetric behavior per IP, session and username
  • Optionally inspects your login responses to count failed versus successful logins

Response inspection works only for CloudFront distributions. ATP works best with the AWS WAF client SDK on the login page, because tokens let it tie attempts to a browser session. It adds labels and per-request fees, so keep it scoped to the login path.

Take quiz
What does ATP primarily protect?
S3 bucket policies
DNS zones
Static image downloads
Login endpoints
Where is ATP response inspection supported?
Network Load Balancers
CloudFront distributions
All resource types equally

40. How does Account Creation Fraud Prevention work in AWS WAF?

Account Creation Fraud Prevention (ACFP) (AWSManagedRulesACFPRuleSet) guards sign-up flows against fake account creation, such as bots farming promo credits.

Configuration is similar to ATP but for registration: you give it the registration page path, the account creation endpoint, and where to find fields like username, password, email, phone number and address.

  • Flags sign-ups using stolen credentials
  • Detects bulk creation from one IP, session or device
  • Evaluates email domains and phone numbers for signs of abuse
  • Uses AWS WAF tokens, so the SDK or Challenge on the registration page is strongly recommended

Like ATP, response inspection to see whether account creation succeeded is available only on CloudFront.

Take quiz
What does ACFP guard against?
Expired certificates
Fraudulent mass account creation
Slow database queries
What must you provide when configuring ACFP?
A VPN configuration
The AWS root account ID
The registration page and account creation endpoint paths

41. How does Shield Advanced application layer automatic mitigation work?

Automatic mitigation lets Shield Advanced respond to HTTP floods without a human writing rules. For a protected resource with a web ACL, Shield learns its normal traffic baseline, and when it spots an attack signature it creates WAF rules in a Shield-managed rule group and applies them in Count or Block mode.

It relies on Route 53 health checks for health-based detection and uses 150 WCUs of the web ACL.

flowchart LR
  A["Baseline learned"] --> B["Attack detected"]
  B --> C["Shield creates WAF rules"]
  C --> D{Mode}
  D -->|Count| E["Observe only"]
  D -->|Block| F["Drop attack traffic"]

Update: AWS is replacing this feature with the WAF Anti-DDoS managed rule group. Per the AWS Security Blog, auto-upgrade of eligible web ACLs begins October 25, 2026 and automatic mitigation is scheduled to retire January 29, 2027. Verify the current timeline before relying on either.

Take quiz
What does Shield automatic mitigation create in your web ACL?
A second CloudFront distribution
New IAM users
WAF rules in a Shield-managed rule group
What is replacing the automatic mitigation feature?
The AWS WAF Anti-DDoS managed rule group
AWS Config
Amazon GuardDuty

42. How does Shield Advanced proactive engagement work?

With proactive engagement, the Shield Response Team contacts you first when an attack seems to be hurting your application, instead of waiting for you to notice and open a case.

  1. Associate a Route 53 health check with the protected resource, one that reflects real application health
  2. Register your emergency contacts: email, phone number and notes for the on-call person
  3. Enable proactive engagement in Shield Advanced
  4. When Shield detects an event and the health check turns unhealthy, the SRT reaches out using those contacts

The health check is the trigger. A check that is too shallow, such as a ping on an unused port, will not fail when the app is really struggling, and the engagement never fires. Keep contacts current, since outdated numbers defeat the point.

Take quiz
What triggers proactive engagement?
A detected event plus an unhealthy Route 53 health check
A scheduled weekly audit
Any 404 response
Why must emergency contacts stay current?
They are used to bill the subscription
The SRT uses them to reach you during an attack
They set the WAF rule priorities

43. When can you request DDoS cost protection credits?

Credits are not automatic. You can ask for them after a DDoS event raised your usage, provided you meet the conditions:

  • The resource was protected by Shield Advanced before the attack (a short lead time is required)
  • For CloudFront and ALB, a web ACL with a rate-based rule was associated
  • The spike in charges came from scaling on a covered service such as EC2, ELB, CloudFront, Global Accelerator or Route 53
  • The event is confirmed as a DDoS attack

You file the claim through AWS Support with the affected resources and time window. The credit covers the extra scaling charges only; the Shield subscription fee and data transfer fees under Shield Advanced still apply. Check the current terms for exact eligibility windows.

Take quiz
Which extra step is needed for CloudFront or ALB credit eligibility?
Enable S3 versioning
Associate a web ACL with a rate-based rule
Run Inspector scans weekly
Which charges does the credit cover?
Unrelated EBS storage costs
The Shield Advanced subscription fee
Scaling charges caused by the attack

44. How do you enable Shield Advanced protection for a resource?

Shield Advanced is a subscription first, then per-resource protections.

  1. Subscribe (one-year commitment). In an AWS Organization the fee is $3,000/month for the whole organization.
  2. Add protection for each resource: CloudFront distribution, Route 53 hosted zone, Global Accelerator, ALB or Classic Load Balancer, or Elastic IP
  3. Associate a web ACL for L7 coverage, and a Route 53 health check for health-based detection
  4. Turn on proactive engagement and add emergency contacts
  5. Optionally grant the SRT access with an IAM role
  6. Create CloudWatch alarms on the DDoSDetected metric
aws shield create-subscription
aws shield create-protection \
  --name prod-alb \
  --resource-arn arn:aws:elasticloadbalancing:us-east-1:111122223333:loadbalancer/app/prod/abc123

Firewall Manager can apply protections across accounts automatically.

Take quiz
What must happen before you can add Shield Advanced protections?
Enable AWS Config rules for S3
Create a VPC peering connection
Subscribe to Shield Advanced
Which metric is commonly alarmed on for DDoS detection in Shield?
DDoSDetected
VolumeIdleTime
CPUUtilization

45. How does Firewall Manager enforce AWS WAF policies across accounts?

A Firewall Manager administrator account creates an AWS WAF policy that contains the rule groups to enforce, plus a scope: which accounts or OUs, which resource types, and optionally which tags. Firewall Manager then creates or updates a web ACL in each in-scope account.

flowchart TD
  A["FM admin account: policy"] --> B["Member account 1"]
  A --> C["Member account 2"]
  A --> D["New account joins OU"]
  B --> E["Web ACL with FM rule groups"]
  C --> F["Web ACL with FM rule groups"]
  D --> G["Policy applied automatically"]

Firewall Manager owns a first and last set of rule groups in each web ACL. Account owners can add their own rules in the middle. With auto-remediation on, existing resources without protection get the web ACL, and drift is corrected. AWS Config must be enabled in the accounts for Firewall Manager to track resources.

Take quiz
Who creates the policy that gets pushed to member accounts?
The Firewall Manager administrator account
The Shield Response Team
Each member account independently
What does auto-remediation do?
Increases the WCU quota
Attaches the policy's protections to non-compliant resources
Deletes unused web ACLs after 30 days

46. How would you design a DDoS-resilient architecture on AWS?

The idea is to absorb attacks at the edge, shrink what is exposed, and scale what remains.

flowchart LR
  U[Users] --> R53["Route 53"]
  R53 --> CF["CloudFront + WAF + Shield"]
  CF --> ALB["ALB in public subnet"]
  ALB --> ASG["Auto Scaling app tier"]
  ASG --> DB[(Private database)]
Layer What to do
Edge Route 53 and CloudFront absorb floods across many locations; Global Accelerator for non-HTTP
Request filtering WAF with rate-based rules, managed groups and the Anti-DDoS rule group
Surface reduction Lock the ALB to CloudFront using the managed prefix list, keep app and DB tiers private
Scale Auto Scaling and load balancing so legitimate load survives
Visibility and response Shield Advanced, CloudWatch alarms, SRT, tested runbooks

The weakest link is often an origin reachable directly by IP. If attackers can bypass CloudFront, the edge protection is wasted.

Take quiz
Why restrict the ALB to CloudFront's managed prefix list?
To remove the need for TLS
So attackers cannot bypass the edge and hit the origin directly
To speed up DNS lookups
Which services form the edge absorption layer?
SQS and SNS
RDS and DynamoDB
Route 53 and CloudFront

47. Explain the execution flow of a request through CloudFront, AWS WAF, and Shield?

In a typical protected setup, traffic passes several checkpoints before your application sees it.

sequenceDiagram
  participant C as Client
  participant D as Route 53
  participant E as CloudFront edge (Shield)
  participant W as AWS WAF web ACL
  participant O as Origin ALB
  C->>D: Resolve domain
  D-->>C: Edge IP
  C->>E: HTTPS request
  E->>E: Shield filters L3/L4 floods
  E->>W: Evaluate rules by priority
  alt Block
    W-->>C: 403 or custom response
  else Allow
    W->>O: Forward request
    O-->>C: Response via CloudFront
  end
  1. DNS resolves to the nearest CloudFront edge, and Route 53 itself is protected by Shield
  2. Shield filters volumetric and protocol attacks before the request is processed
  3. The WAF web ACL evaluates rules in priority order and either blocks or lets the request through
  4. Allowed requests go to the origin, which can run its own regional web ACL
  5. Logs and metrics are produced for each decision
Take quiz
What happens first for network floods in this flow?
The WAF default action runs
The origin database rejects it
Shield filters L3/L4 attack traffic at the edge
What happens when a WAF rule blocks the request?
The client gets a 403 or custom response without the origin seeing it
The origin processes it anyway
CloudFront retries it three times

48. How does managed rule group versioning work in AWS WAF?

Many AWS Managed Rules groups are versioned. By default, your web ACL uses the default version, which AWS updates over time as it adds or tunes rules. That keeps you current, but a rule change can occasionally affect traffic that used to pass.

You can instead pin a static version. The behavior stays frozen until you move it yourself, which gives you a controlled upgrade path.

  1. Subscribe to the managed rule group's SNS notifications, so you hear about new versions and updates
  2. Create a test web ACL (or a duplicate rule) pointing at the new version, with actions overridden to Count
  3. Compare matches to the current version using logs
  4. Switch production to the new version when it looks safe

Static versions do not last forever. AWS eventually retires old ones, so pinning is a delay tactic, not a permanent setting.

Take quiz
What does pinning a static version of a managed group give you?
Frozen rule behavior until you choose to upgrade
Automatic updates every day
Free usage of all paid groups
What is the safe way to adopt a new managed rule version?
Switch production immediately
Test it in Count mode against real traffic first
Delete the old version

49. How can you optimize AWS WAF cost?

WAF cost is mostly requests, rules and extras. Know the pricing parts first: a monthly fee per web ACL ($5), a monthly fee per rule or rule group ($1 each), a per-million-request charge, and add-ons for WCUs beyond 1,500, larger body inspection and the intelligent threat groups.

  • Share one web ACL across many resources where the rules fit; the web ACL fee is per ACL
  • Scope down Bot Control, ATP, ACFP and Anti-DDoS to the paths that need them
  • Order rules so cheap Allow and Block rules (IP sets, geo) run before expensive inspection
  • Replace many IP rules with a single IP set and avoid regex pattern sets (25 WCUs)
  • Keep body inspection at the default unless you truly need more
  • Use logging filters to avoid storing every allowed request
  • If you run Shield Advanced, use the WAF fee waiver on protected resources

Always check the current price list. Rates change by Region and feature.

Take quiz
Which rule type is cheapest in WCUs and good to run early?
Regex pattern set match
IP set match
Bot Control targeted level
Which change usually reduces logging cost?
Enabling full body logging
Logging to three destinations at once
A logging filter that drops most allowed requests

50. How do you manage AWS WAF configuration as code?

Treat the web ACL like application code: define it in CloudFormation, Terraform or CDK, review it in pull requests and deploy it through a pipeline.

Resources:
  AppWebAcl:
    Type: AWS::WAFv2::WebACL
    Properties:
      Scope: REGIONAL
      DefaultAction: { Allow: {} }
      VisibilityConfig:
        SampledRequestsEnabled: true
        CloudWatchMetricsEnabled: true
        MetricName: AppWebAcl
      Rules:
        - Name: CommonRules
          Priority: 10
          OverrideAction: { None: {} }
          Statement:
            ManagedRuleGroupStatement: { VendorName: AWS, Name: AWSManagedRulesCommonRuleSet }
          VisibilityConfig:
            SampledRequestsEnabled: true
            CloudWatchMetricsEnabled: true
            MetricName: CommonRules

  • Keep IP sets and custom rule groups as separate resources so they can be updated alone
  • Size rule group capacity carefully, since changing it forces a replacement
  • Ship new rules in Count first, then promote to Block in a later commit
  • Use drift detection, and remember Firewall Manager or Shield changes can alter a web ACL outside your template
Take quiz
Why keep IP sets as separate resources in your template?
It removes WCU costs
It is required by CloudFormation
They can be updated without redeploying the whole web ACL
What is a safe way to release a new rule through a pipeline?
Deploy it in Count mode first, then promote to Block
Skip code review for WAF changes
Deploy it straight to Block in production without testing
«
»

Comments & Discussions