Cloud / AWS WAF & Shield Interview questions
Last updated
1. What is AWS WAF?
AWS WAF is a managed web application firewall that filters HTTP and HTTPS requests at Layer 7 before they reach your application. You write rules that look at the IP address, headers, URI, query string, cookies or body, and each rule decides whether to allow, block, count or challenge the request.
It sits in front of CloudFront, Application Load Balancer, API Gateway (REST), AppSync, Cognito user pools, App Runner and Verified Access. Typical uses are blocking SQL injection and cross-site scripting, rate limiting abusive clients, filtering by country and keeping bad bots away.
Pricing is pay-as-you-go: you pay per web ACL, per rule and per million requests inspected. There is no hardware or software to manage.
Take quiz
Layer 2 (data link layer)
Layer 7 (application layer)
Layer 3 (network layer)
Only the TCP window size
Only the source MAC address
Headers, URI, query string and body
Only the DNS resolver used
2. What is AWS Shield?
AWS Shield is AWS's managed DDoS (Distributed Denial of Service) protection service. It detects and absorbs floods of malicious traffic aimed at your applications so legitimate users keep getting through.
It comes in two tiers. Shield Standard is on by default for every AWS customer at no extra charge and covers common network and transport layer (L3/L4) attacks. Shield Advanced is a paid subscription that adds L7 protection, attack visibility, 24/7 access to the Shield Response Team and DDoS cost protection.
Shield does not inspect request content the way a firewall does. It focuses on volume and protocol abuse, and it is usually paired with AWS WAF for application-layer rules.
Take quiz
SQL injection in form fields
Unpatched operating systems
DDoS attacks
Leaked IAM access keys
Shield Premium
Shield Advanced
Shield Enterprise
Shield Standard
3. What are the two tiers of AWS Shield?
AWS Shield has Shield Standard and Shield Advanced.
| Shield Standard | Shield Advanced | |
| Cost | Free, included for everyone | $3,000/month per organization, 1-year commitment, plus data transfer fees |
| Setup | Always on, nothing to enable | Subscribe, then add protections per resource |
| Layers covered | L3 and L4 | L3, L4 and L7 (with AWS WAF) |
| Expert help | None | 24/7 Shield Response Team (needs Business or Enterprise Support) |
| Cost protection | No | Credits for DDoS-driven scaling charges |
Advanced covers CloudFront, Route 53 hosted zones, Global Accelerator, Elastic Load Balancing and Elastic IPs.
Take quiz
Both tiers
Shield Standard
Neither tier
Shield Advanced
Only AWS WAF customers
Shield Advanced
Shield Standard
4. What is a web ACL in AWS WAF?
A web ACL (web access control list) is the container that holds your AWS WAF rules and rule groups, plus a default action (Allow or Block) for requests that match nothing. You associate it with one or more protected resources, and every request to those resources is evaluated against it.
A resource can have only one web ACL at a time, but one web ACL can protect many resources. A web ACL also has a scope: CLOUDFRONT (global, created in us-east-1) or REGIONAL (tied to a Region). Rules inside it run in priority order, lowest number first.
Newer console screens may label it a protection pack, but the API and most documentation still say web ACL.
Take quiz
One
As many as you like
None, rules attach directly to the resource
Up to five
Forwards it to AWS Shield for review
Applies its default action
Drops it silently with no log
Sends it to the Shield Response Team
5. What AWS resources can you protect with AWS WAF?
AWS WAF attaches to a specific set of front-door services rather than to arbitrary compute:
- Amazon CloudFront distributions
- Application Load Balancers
- Amazon API Gateway REST APIs (at the stage level)
- AWS AppSync GraphQL APIs
- Amazon Cognito user pools
- AWS App Runner services
- AWS Verified Access instances
- Amazon Bedrock AgentCore Gateway
Network Load Balancers, EC2 instances and API Gateway HTTP APIs cannot take a web ACL directly. The usual workaround is putting CloudFront or an ALB in front of them.
Take quiz
Application Load Balancer
Network Load Balancer
AppSync GraphQL API
CloudFront distribution
Put an ALB or CloudFront in front and attach the web ACL there
Install the web ACL as an agent on the instance
Attach the web ACL to the security group
6. What is a rule in AWS WAF?
A rule tells AWS WAF what to look for and what to do when it finds it. It has a name, a priority, a statement (the match logic), an action and a visibility configuration for CloudWatch metrics and sampled requests.
Statements can be simple, like an IP set match, or nested with AND, OR and NOT to build conditions such as 'URI starts with /admin AND country is not US'. Rules you reuse can be grouped into a rule group, and AWS or Marketplace sellers publish managed rule groups you can drop in.
{ "Name": "BlockAdminFromOutside", "Priority": 10, "Statement": { "ByteMatchStatement": { "SearchString": "/admin", "FieldToMatch": { "UriPath": {} }, "TextTransformations": [{ "Priority": 0, "Type": "NONE" }], "PositionalConstraint": "STARTS_WITH" } }, "Action": { "Block": {} }, "VisibilityConfig": { "SampledRequestsEnabled": true, "CloudWatchMetricsEnabled": true, "MetricName": "BlockAdmin" } }
Take quiz
The default action
The log destination
The statement
The scope
Chain them with Lambda functions
Nest statements with AND, OR and NOT
You cannot, one condition per rule only
7. What actions can an AWS WAF rule take?
A rule can take one of five actions:
| Action | What happens |
| Allow | Request is passed on, rule evaluation stops. Can add custom request headers. |
| Block | Request is rejected, evaluation stops. Default 403, or a custom response. |
| Count | Request is only counted and logged, evaluation continues. |
| CAPTCHA | Serves a puzzle unless the client holds a valid, unexpired token. |
| Challenge | Runs a silent browser check unless the client holds a valid token. |
Allow and Block are terminating. Count is non-terminating, which is why it is the safe way to test a new rule before enforcing it.
Take quiz
CAPTCHA
Allow
Block
Count
Challenge
CAPTCHA
Count
Allow
8. What are AWS Managed Rules?
AWS Managed Rules are rule groups written and updated by AWS security teams, so you get tested protections without authoring regexes yourself. You add a rule group to your web ACL as one reference and AWS maintains the rules behind it.
The baseline groups include the Core rule set (OWASP-style protections), Admin protection and Known bad inputs. Use-case groups cover SQL database, Linux, POSIX, PHP and Windows exploits. IP reputation groups cover Amazon IP reputation and Anonymous IP lists.
Intelligent threat groups, such as Bot Control, Account Takeover Prevention, Account Creation Fraud Prevention and Anti-DDoS, are paid add-ons with extra fees. Third-party sellers also offer managed groups on AWS Marketplace.
Take quiz
AWS
You, through scheduled Lambda jobs
Your CloudFront distribution
The Shield Response Team on request only
Core rule set
Account Takeover Prevention
Admin protection
Amazon IP reputation list
9. What is a rate-based rule in AWS WAF?
A rate-based rule counts requests from each client over a time window and takes action once a client crosses your limit. It is the standard answer to HTTP floods, brute-force logins and scrapers.
By default it groups requests by source IP. You set a limit (minimum 10) and the window, then choose Block, Count, CAPTCHA or Challenge. When the client's rate drops back under the limit, the action stops being applied automatically.
A single rate-based rule can track up to 10,000 distinct IPs being rate limited at once, and a web ACL can hold up to 10 of them.
Take quiz
Unencrypted HTTP traffic
Request floods and brute-force attempts
Cross-region replication lag
Expired TLS certificates
The web ACL is deleted
The rule stops applying its action to that client
The client stays blocked until you edit the rule
10. What is an IP set in AWS WAF?
An IP set is a reusable list of IPv4 or IPv6 addresses in CIDR notation that rules can reference. Instead of writing hundreds of addresses into a rule, you keep them in the set and point a rule at it with an IP set reference statement.
Each set holds up to 10,000 addresses, and you can update it without touching the rule. That makes it a good fit for office allow lists, partner ranges and block lists fed by a threat feed.
An IP set match is also one of the cheapest conditions in WCU terms, so it is worth using before heavier regex rules.
Take quiz
Hostnames only
MAC addresses
CIDR notation
ASN numbers only
It removes the need for logging
It bypasses the web ACL default action
You can update the list without editing the rule
11. What is the default action of a web ACL?
The default action is what the web ACL does with a request that matches no rule with a terminating action. You must pick either Allow or Block when you create the web ACL.
Most public websites use Allow as the default and add Block rules for known bad traffic. Internal or partner-only APIs often flip it: default Block, plus explicit Allow rules for approved IP ranges or headers.
Like rule actions, the default action can carry custom response codes and headers, so a blocked client can get a friendly 403 page instead of the stock message.
Take quiz
Only when AWS Shield is subscribed
Before any rule is evaluated
When no rule with a terminating action matches
Block, with Allow rules for the approved IPs
CAPTCHA for everyone
Count, with no other rules
Allow, with no other rules
12. What are web ACL capacity units (WCUs)?
WCUs are a measure of how much processing power your rules need. Each rule costs a number of units based on its complexity: an IP set match costs 1, while a regex pattern set match costs 25.
A rule group's capacity is fixed when you create it and cannot be changed later, so you have to size it up front. A rule group can use up to 5,000 WCUs, and so can a web ACL.
The base web ACL price includes 1,500 WCUs. Going past that adds a per-request fee in tiers, so WCUs affect both design limits and your bill. They do not change how deeply AWS WAF inspects traffic.
Take quiz
1,500
5,000
10,000
500
It grows automatically with traffic
It is fixed at creation and cannot be changed later
It resets every month
13. What types of attacks does AWS WAF block?
AWS WAF works on web traffic, so it targets application-layer threats:
- Injection attacks - SQL injection and command injection patterns in query strings, headers or bodies
- Cross-site scripting (XSS) - script payloads in request fields
- Known exploit patterns - for example Log4j-style payloads and path traversal
- HTTP floods - via rate-based rules and the Anti-DDoS rule group
- Bots and scrapers - through Bot Control and CAPTCHA or Challenge
- Credential abuse - stuffing and fake sign-ups via ATP and ACFP
- Unwanted sources - by country, ASN, or IP reputation
It does not stop volumetric network floods such as SYN or UDP floods. That is Shield's job.
Take quiz
Physical theft of a server
SQL injection in a request parameter
UDP reflection attack
SYN flood on the network layer
AWS Config
Amazon Inspector
AWS Shield
AWS WAF
14. What DDoS attacks does Shield Standard mitigate?
Shield Standard defends against the most common infrastructure-layer (L3 and L4) DDoS attacks, using always-on detection and inline mitigation in the AWS network.
- SYN and ACK floods that exhaust connection tables
- UDP floods
- Reflection and amplification attacks such as DNS or NTP reflection
It needs no configuration and costs nothing. It gives the strongest protection when your app is behind CloudFront and Route 53, because attack traffic is absorbed at the edge. It does not cover Layer 7 floods, which need WAF rules or Shield Advanced.
Take quiz
Credential stuffing
Cross-site scripting
SYN flood
SQL injection
No, it is always on
Yes, per resource through the console
Yes, by buying a subscription
15. What is the AWS Shield Response Team (SRT)?
The Shield Response Team (SRT) is a group of AWS DDoS specialists you can call on during an attack if you subscribe to Shield Advanced and have a Business or Enterprise Support plan. You open a case and they help triage, analyze traffic and suggest mitigations.
If you grant them access, the SRT can write or adjust AWS WAF rules in your account on your behalf during an event. You give that permission through a dedicated IAM role, and optionally let them read your WAF logs in S3.
The team used to be called the DDoS Response Team (DRT), and you may still see that name in older docs and API calls.
Take quiz
An IAM role granting it access
A VPN tunnel into your VPC
Your root account password
Shield Rapid Operations
DDoS Response Team (DRT)
Cyber Defense Unit
16. What is DDoS cost protection in Shield Advanced?
DDoS cost protection is a Shield Advanced benefit that lets you request AWS service credits for usage spikes caused by a DDoS attack. If your protected resources scale out under attack, you are not stuck paying for that surge.
It covers scaling charges on protected Amazon EC2, Elastic Load Balancing, CloudFront, Global Accelerator and Route 53 resources. You file the request through the normal AWS Support channel after the event.
It is a credit for scaling cost, not a refund of the Shield subscription itself.
Take quiz
Scaling charges triggered by an attack
Developer salaries during the incident
The $3,000 monthly Shield fee
Lost revenue from downtime
Automatically on your next invoice with no request
By emailing the Route 53 team
Through AWS Support
17. What is AWS Firewall Manager?
AWS Firewall Manager lets a central security team define firewall policies once and enforce them across every account in an AWS Organization. Instead of configuring AWS WAF in 40 accounts by hand, you create one policy and Firewall Manager applies it.
It manages AWS WAF, Shield Advanced, VPC security groups, Network Firewall, Route 53 Resolver DNS Firewall and more. Policies are scoped by account, organizational unit, resource type or tag, and new resources that match the scope are covered automatically.
It requires AWS Organizations, a designated Firewall Manager administrator account, and AWS Config enabled in the member accounts.
Take quiz
Replace CloudTrail
Centrally enforce firewall policies across accounts
Run penetration tests
Store TLS certificates
AWS Direct Connect
Amazon Macie
AWS Organizations
Amazon Athena
18. What are labels in AWS WAF?
Labels are tags that a rule attaches to a request while it is being evaluated. A later rule in the same web ACL can match on that label, which lets you split detection from decision.
Managed rule groups use labels heavily. For example, Bot Control labels a request as a verified bot or a scraper, and you can write your own rule that allows one label and rate limits another instead of accepting the group's built-in action.
Labels exist only for that request inside that web ACL. They are not sent to your origin, but they do show up in WAF logs and CloudWatch metrics. A rule can only read labels added by rules with a lower priority number, because those run first.
Take quiz
Uses the Block action
Lives in a different AWS account
Runs earlier, with a lower priority number
Runs later, with a higher priority number
In the Route 53 query log
In WAF logs and CloudWatch metrics
Only inside the origin application's headers by default
19. How do you enable logging in AWS WAF?
Logging is enabled per web ACL, not account-wide. You pick one destination and AWS WAF writes a JSON record for each inspected request.
| Destination | Good for |
| CloudWatch Logs log group | Quick searches with Logs Insights and alarms |
| S3 bucket | Cheap long-term storage and Athena queries |
| Data Firehose stream | Streaming to Splunk, OpenSearch or another SIEM |
The destination name must start with aws-waf-logs-. In the console, open the web ACL, go to Logging and metrics, enable logging and choose the destination. Each record includes the action, the terminating rule, matched labels and full request details such as headers and URI.
Take quiz
aws-shield-
cloudtrail-waf-
waf-audit-
aws-waf-logs-
Per Region for the whole account
Per IP set
Per web ACL
Data Firehose
AWS Config rules
IAM Access Analyzer
20. List the main match conditions you can use in AWS WAF rules?
AWS WAF statements can match on many parts of a request:
- IP address - single IP, CIDR range or IP set
- Geo match - by country, plus ASN match for network owner
- String match - contains, starts with, ends with, exactly, or regex
- SQLi and XSS match - built-in detection on a chosen field
- Size constraint - length of body, header, query string or URI
- Label match - react to labels set by earlier rules
- Rate-based - count requests per key over a window
- Rule group reference - your own or managed rule groups
The part of the request to inspect (URI path, query string, a named header, cookies, JSON body, method) is chosen with a 'field to match', and text transformations such as URL decoding can be applied first. Any of these can be combined with AND, OR and NOT.
Take quiz
Label match
Geo match
IP set reference
Size constraint
Normalize the input, for example URL-decode it, before matching
Translate the request into another language
Encrypt the request body
21. What is the AWS WAF Bot Control rule group?
Bot Control (AWSManagedRulesBotControlRuleSet) is a paid managed rule group that detects and manages automated traffic. It comes in two inspection levels.
- Common - identifies self-declared bots by user agent and verifies well-known ones, such as search engines, through reverse DNS
- Targeted - goes after evasive bots using browser interrogation, fingerprinting and behavior analysis, and relies on CAPTCHA or Challenge tokens
Instead of blocking everything, it mostly labels traffic by category (verified bot, scraper, HTTP library and so on). You then decide per label: allow search engines, count monitoring tools, block scrapers. Because it adds per-request fees, scope it down to the paths that matter.
Take quiz
Self-identifying bots and verified bots
SQL injection payloads
Only credential-stuffing tools
Run it on every request in the web ACL with no limits
Use a scope-down statement to limit what it inspects
Disable logging
22. What is the difference between AWS WAF and AWS Shield?
They solve different problems and are meant to be used together. WAF looks at what a request says; Shield looks at how much traffic is arriving and whether it abuses the network protocol.
| AWS WAF | AWS Shield | |
| Protects against | Injection, XSS, bots, request floods, unwanted sources | DDoS attacks |
| Layer | Layer 7 (HTTP/HTTPS) | L3/L4 (Standard), L3/L4/L7 (Advanced) |
| You configure | Web ACLs, rules, rule groups | Nothing (Standard), protections and health checks (Advanced) |
| Pricing | Per web ACL, rule and request | Free (Standard), $3,000/month (Advanced) |
| Attached to | CloudFront, ALB, API Gateway and others | CloudFront, Route 53, Global Accelerator, ELB, Elastic IP |
A SQL injection attempt is a WAF problem. A 500 Gbps UDP flood is a Shield problem. An HTTP flood is where the two overlap, and Shield Advanced uses WAF rules to mitigate it.
Take quiz
AWS KMS
AWS Shield Standard
AWS WAF
Amazon Route 53
AWS WAF web ACLs
Firewall Manager policies
Shield Advanced protections
Shield Standard
23. When should you choose Shield Advanced over Shield Standard?
Stay on Standard if an outage from a DDoS would be annoying but not costly. Move to Advanced when downtime or surprise bills would hurt. Typical triggers:
- Revenue-critical sites such as e-commerce, gaming, fintech or media streaming
- You have been targeted before, or expect extortion-style (ransom DDoS) attempts
- You need L7 DDoS detection and mitigation without building it all yourself
- You want the Shield Response Team on call and proactive engagement
- Your workload autoscales heavily and a flood could generate a large bill
- Compliance or customers expect documented DDoS protections
The $3,000 monthly fee covers the whole organization, so it is easier to justify when many accounts share it. Remember that SRT access also requires a Business or Enterprise Support plan, which is an extra cost to plan for.
Take quiz
A dev sandbox that is rarely used
A static personal blog with no revenue
A revenue-critical app that autoscales and has been targeted before
A Business or Enterprise Support plan
A Route 53 private hosted zone
A dedicated Direct Connect link
24. How does AWS WAF evaluate rules in a web ACL?
AWS WAF checks rules in ascending priority order: the lowest number runs first. As soon as a rule with a terminating action (Allow or Block) matches, evaluation stops and that action is applied.
Non-terminating actions such as Count do not stop the flow. The request moves on to the next rule, and any labels or counts are recorded along the way. If it passes every rule without a terminating match, the web ACL default action decides its fate.
flowchart TD
A["Request arrives"] --> B{Next rule by priority}
B -->|Match + Allow or Block| C["Apply action and stop"]
B -->|Match + Count| D["Count and label"]
D --> B
B -->|No match| B
B -->|No rules left| E["Apply default action"]
This is why order matters. Put a cheap Allow for trusted IPs near the top and block rules before expensive inspection.
Take quiz
Evaluation stops and the request is blocked
The request is sent to the default action
The rest of the rules still run and may override it
Random order each time
Lowest priority number first
Highest priority number first
Alphabetically by rule name
25. Why should you deploy new rules in Count mode first?
Count mode lets a rule match and be logged without affecting the request, so you can see what it would have blocked before it blocks anything real. New rules, especially regex and managed groups, can catch legitimate traffic you did not think of.
- Add the rule with the action set to Count (or override a managed rule's action to Count)
- Watch CloudWatch metrics, sampled requests and WAF logs for a few days across peak traffic
- Check whether matches are real attacks or valid users, such as large form posts or API clients
- Tune or scope the rule, then switch to Block
Count also still adds labels, so you can build label-based logic while the rule is in observation. Skipping this step is a common reason a new rule causes an outage on release day.
Take quiz
Blocks the request and logs it
Records the match and lets evaluation continue
Deletes the rule automatically
To disable CloudWatch metrics
To reduce the web ACL price
To find false positives before enforcing
26. What is the difference between CloudFront and regional web ACLs?
A web ACL has one of two scopes, chosen at creation, and it cannot be changed afterwards.
| CLOUDFRONT scope | REGIONAL scope | |
| Protects | CloudFront distributions | ALB, API Gateway, AppSync, Cognito, App Runner, Verified Access |
| Where it lives | Global, managed in US East (N. Virginia) us-east-1 | In the same Region as the resource |
| Where traffic is filtered | At CloudFront edge locations | In the Region, at the resource |
| Body inspection default | 16 KB, up to 64 KB | ALB and AppSync fixed at 8 KB; others 16 KB default |
Rule groups, IP sets and regex sets also have a scope and cannot be shared across scopes. To cover both a CloudFront distribution and an ALB, you need two web ACLs, and Firewall Manager can keep them in sync.
Take quiz
In the Region closest to the origin
eu-west-1 only
US East (N. Virginia), us-east-1
In any Region you like
No, scopes cannot be mixed
Yes, always
Yes, if you enable cross-scope sharing
27. What happens when a request body exceeds the inspection limit?
AWS WAF only inspects the first part of a body. For ALB and AppSync that limit is a fixed 8 KB. For CloudFront, API Gateway, Cognito, App Runner and Verified Access it is 16 KB by default and can be raised up to 64 KB (extra fee per additional 16 KB).
What WAF does next is set per rule through oversize handling:
- CONTINUE - inspect the portion available and judge on that
- MATCH - treat the oversized request as a match
- NO_MATCH - treat it as not matching
This is a real bypass route. An attacker can pad a payload with junk so the malicious part sits beyond the limit. The fix is a size constraint rule that blocks bodies over the limit on endpoints that never need big payloads, and a separate allowance for upload paths. Headers and cookies have similar limits (first 8 KB or 200 items).
Take quiz
Pad the request so the payload falls past the inspected portion
Send the request over IPv6
Use a longer domain name
8 KB
1 MB
64 KB
There is no limit
28. How does a rate-based rule count requests?
A rate-based rule keeps a running count per aggregation key over a sliding time window and acts once that count passes your limit.
- Window - 1, 2, 5 or 10 minutes (5 is the default)
- Limit - the request threshold per key, minimum 10
- Key - source IP by default, or forwarded IP, header, cookie, query argument, URI path, HTTP method, label namespace, JA3 or JA4 fingerprint, and combinations of these
- Scope-down - an optional statement to count only a subset, such as POST /login
Custom keys are what make it useful beyond plain IP limits. For example, you can cap each API key or each session cookie separately, so a shared corporate NAT address does not lock out a whole office. Enforcement is not instant; expect a short delay between crossing the threshold and the action starting.
Take quiz
Source IP address
Request body hash
AWS account ID
Hostname of the origin
To bypass the window setting
To disable the rate limit
To limit each caller separately instead of lumping users behind one IP
29. When should you use a scope-down statement?
A scope-down statement narrows which requests a rule or managed rule group looks at. You use it when only part of your traffic needs the check, which makes rules both more accurate and cheaper.
- Rate limit only /login or /api/search instead of the whole site
- Run Bot Control, ATP or ACFP only on sensitive paths, since they charge per inspected request
- Skip inspection for a known-safe path that keeps triggering a managed rule
- Apply a rule only to a specific host header in a shared web ACL
"ScopeDownStatement": { "ByteMatchStatement": { "SearchString": "/login", "FieldToMatch": { "UriPath": {} }, "TextTransformations": [{ "Priority": 0, "Type": "NONE" }], "PositionalConstraint": "STARTS_WITH" } }
One exception: AWS recommends against scope-down on the Anti-DDoS rule group, since it needs to see all traffic.
Take quiz
To turn off labels
To make it block all other paths
To reduce per-request inspection fees and focus on sensitive traffic
Anti-DDoS
Bot Control
Account Takeover Prevention
30. How does AWS WAF detect SQL injection and XSS?
AWS WAF has built-in SQLi and XSS match statements. You pick which part of the request to inspect (query string, body, a header, cookies) and the engine looks for attack syntax rather than a fixed string.
Text transformations make the check harder to evade. URL decoding, HTML entity decoding and lowercase conversion run first, so an encoded payload like %27%20OR%201%3D1 is normalized before matching. The SQLi statement also has a sensitivity level, LOW or HIGH; HIGH catches more but can raise false positives.
You can skip writing these yourself by using the AWS Managed Rules SQL database group and the Core rule set. Remember that WAF is a safety net. The real fix is parameterized queries and output encoding in the application.
Take quiz
So encoded payloads are normalized before matching
To compress the request body
To hide the request from CloudWatch
It only inspects the URI
Catches more attacks but may flag legitimate requests
Faster responses with lower accuracy
31. How do you identify the real client IP behind a proxy in AWS WAF?
If CloudFront or another proxy sits in front of your ALB, the ALB-level web ACL sees the proxy's address as the source. IP rules, geo match and rate limits would then hit the wrong address.
The fix is the forwarded IP configuration. You tell the rule to read the client address from a header, usually X-Forwarded-For, and choose which entry to use (first, last or any). You also set a fallback behavior, MATCH or NO_MATCH, for requests where the header is missing or malformed.
This works for IP set match, geo match and rate-based rules. Keep in mind that clients can forge X-Forwarded-For, so trust it only when a proxy you control sets it. Attaching the web ACL at CloudFront, the true edge, avoids the problem.
Take quiz
IPv6 hides all addresses
A proxy such as CloudFront sits in front and its IP is the source
WAF always masks client IPs
Which Region the logs go to
The size of the IP set
How to treat requests with a missing or invalid header
32. What happens when a web ACL exceeds 1,500 WCUs?
Nothing breaks. A web ACL can use up to 5,000 WCUs, and the 1,500 mark is simply where the base price stops. Beyond it, AWS WAF adds a request charge in tiers, currently $0.20 per million requests for each additional 500 WCUs used.
The hard limit is 5,000. Past that, you cannot add rules, and a rule group's own capacity cannot exceed 5,000 either. Since rule group capacity is permanent, you have to rebuild the group to change it.
Ways to stay under the line: replace many IP rules with one IP set, avoid regex pattern sets (25 WCUs each), drop duplicate or overlapping rules, and check the capacity of each managed group before adding it.
Take quiz
5,000
2,500
Unlimited
1,500
Merging many IP rules into a single IP set
Duplicating rules for redundancy
Adding more regex pattern sets
33. How do CAPTCHA and Challenge actions work?
Both actions check whether the client holds a valid AWS WAF token. If it does, the request passes. If not, WAF blocks the request and sends a check instead.
| CAPTCHA | Challenge | |
| What the user sees | A puzzle to solve | Nothing, runs silently in the browser |
| Best for | Suspicious traffic where a human can reasonably help | Filtering simple bots with zero friction |
Once the client solves the check, it gets a token stored as a cookie, and the immunity time (default 300 seconds) decides how long the token is trusted before another check. These actions work for normal browser page loads. For fetch or XHR calls, mobile apps or single-page apps, you integrate the AWS WAF JavaScript or mobile SDK so the client can fetch and attach tokens itself.
Take quiz
CAPTCHA shows a puzzle; Challenge runs silently
CAPTCHA needs Shield Advanced; Challenge does not
Challenge always blocks; CAPTCHA always allows
The size of the request body inspected
How long a valid token is trusted before re-checking
The rate limit window
34. How do you redact sensitive fields and filter AWS WAF logs?
Raw WAF logs can hold tokens, passwords in query strings or cookies you would rather not store. Two logging settings handle that:
- Redacted fields - choose request parts to mask in the logs: URI path, query string, a named header, the HTTP method, or the body (JSON body fields). The value is replaced, but the rest of the record stays intact.
- Logging filter - keep or drop records by condition, for example keep only Block and Count, or only requests carrying a specific label.
Filtering matters for cost. Logging every allowed request on a busy site can dwarf your WAF bill in S3 or CloudWatch Logs ingestion. A common pattern is to log blocked and counted requests plus a labeled sample of allowed ones, then use Athena over S3 for investigations.
Take quiz
Deletes the web ACL
Masks that part of the request in the log record
Blocks requests containing the field
To speed up rule evaluation
To enable CAPTCHA
To keep only the records you need and control log costs
35. How does the AWS WAF Anti-DDoS managed rule group work?
The Anti-DDoS managed rule group (AWSManagedRulesAntiDDoSRuleSet) watches traffic to the web ACL, learns what normal looks like, and detects HTTP request floods. It labels requests, marks the likely attackers by suspicion level and then challenges or blocks them.
- Every inspected request gets labels such as event-detected and low, medium or high suspicion
- Challenge can run silently in the browser, and you can exempt non-HTML paths such as APIs
- Sensitivity (Low, Medium, High) is set separately for Block and Challenge
- It needs 50 WCUs and no Route 53 health checks
Place it at the highest priority, or right under custom Allow rules, so it sees as much traffic as possible. Any customer can use it for an added fee, and Shield Advanced subscribers get it included. During active mitigation, blocked attack requests are excluded from request charges.
Take quiz
After all other rules
In a separate account
At the highest priority, below any custom Allow rules
Suspicion-level labels such as high-suspicion-ddos-request
A copy of the request body
Only the client's country
36. How do you troubleshoot legitimate requests blocked by AWS WAF?
Start with evidence from the logs, not guesses. Each blocked record names the rule that stopped the request.
- Ask for the time, URL and client IP, or a request ID from the 403 page
- Find the entry in WAF logs or sampled requests and read terminatingRuleId and ruleGroupList to see which rule fired
- If it came from a managed group, note the exact sub-rule, for example a body size or XSS rule
- Switch only that sub-rule to Count with a rule action override
- Add a narrow exception: a scope-down or a label-based Allow for that path, not a blanket Allow
- Re-test and monitor the Count metrics before turning it back to Block
fields @timestamp, httpRequest.clientIp, httpRequest.uri, terminatingRuleId, action | filter action = 'BLOCK' and httpRequest.uri like /checkout/ | sort @timestamp desc | limit 50
Avoid disabling the whole rule group. That removes protection for every other path.
Take quiz
terminatingRuleId
httpVersion
httpRequest.clientIp
timestamp
Disable the entire managed rule group
Override that sub-rule to Count and add a narrow exception
Delete the whole web ACL
37. How do you protect an API Gateway REST API with AWS WAF?
Create a regional web ACL in the same Region as the API, then associate it with the API's stage. WAF runs before the request reaches your integration, so blocked calls never invoke a Lambda or backend.
aws wafv2 associate-web-acl \ --web-acl-arn arn:aws:wafv2:us-east-1:111122223333:regional/webacl/api-acl/abcd1234 \ --resource-arn arn:aws:apigateway:us-east-1::/restapis/a1b2c3/stages/prod
Association is per stage, so dev and prod can have different web ACLs. Only REST APIs are supported. HTTP APIs and WebSocket APIs cannot take a web ACL directly, so place CloudFront in front of them.
Useful rules for APIs: a rate-based rule keyed on the API key or Authorization header, the Core rule set and Known bad inputs groups, and an IP allow list for partner-only endpoints. WAF complements API Gateway throttling and usage plans, it does not replace them.
Take quiz
The account
The stage
The VPC
Each individual Lambda function
WebSocket API
HTTP API
REST API
38. How can you return a custom response from AWS WAF?
A Block action can return your own status code, headers and body instead of the default 403. This is handy for a branded error page, a 429 on rate limiting, or a JSON error for API clients.
- Define a custom response body at the web ACL level with a key, content type (text, JSON or HTML) and content
- In the rule's Block action, enable custom response and set the status code and any headers
- Reference the body by its key
The combined size of all custom response bodies in a web ACL or rule group is capped at 50 KB.
Other actions can add things too. Allow, Count, CAPTCHA and Challenge can insert custom request headers. WAF prefixes them with x-amzn-waf-, so your origin can see a tag such as which rule matched and handle that traffic differently.
Take quiz
x-shield-
x-forwarded-
x-amzn-waf-
x-aws-block-
Count
None, the response is fixed
Allow only
Block
39. How does Account Takeover Prevention work in AWS WAF?
Account Takeover Prevention (ATP) is a managed rule group (AWSManagedRulesATPRuleSet) that protects login endpoints from stolen credential use, credential stuffing and brute force.
You tell it your login path and how credentials are sent (field names for username and password, JSON or form encoded). ATP then does three things:
- Checks submitted credentials against a database of known-compromised credentials
- Tracks volumetric behavior per IP, session and username
- Optionally inspects your login responses to count failed versus successful logins
Response inspection works only for CloudFront distributions. ATP works best with the AWS WAF client SDK on the login page, because tokens let it tie attempts to a browser session. It adds labels and per-request fees, so keep it scoped to the login path.
Take quiz
S3 bucket policies
DNS zones
Static image downloads
Login endpoints
Network Load Balancers
CloudFront distributions
All resource types equally
40. How does Account Creation Fraud Prevention work in AWS WAF?
Account Creation Fraud Prevention (ACFP) (AWSManagedRulesACFPRuleSet) guards sign-up flows against fake account creation, such as bots farming promo credits.
Configuration is similar to ATP but for registration: you give it the registration page path, the account creation endpoint, and where to find fields like username, password, email, phone number and address.
- Flags sign-ups using stolen credentials
- Detects bulk creation from one IP, session or device
- Evaluates email domains and phone numbers for signs of abuse
- Uses AWS WAF tokens, so the SDK or Challenge on the registration page is strongly recommended
Like ATP, response inspection to see whether account creation succeeded is available only on CloudFront.
Take quiz
Expired certificates
Fraudulent mass account creation
Slow database queries
A VPN configuration
The AWS root account ID
The registration page and account creation endpoint paths
41. How does Shield Advanced application layer automatic mitigation work?
Automatic mitigation lets Shield Advanced respond to HTTP floods without a human writing rules. For a protected resource with a web ACL, Shield learns its normal traffic baseline, and when it spots an attack signature it creates WAF rules in a Shield-managed rule group and applies them in Count or Block mode.
It relies on Route 53 health checks for health-based detection and uses 150 WCUs of the web ACL.
flowchart LR
A["Baseline learned"] --> B["Attack detected"]
B --> C["Shield creates WAF rules"]
C --> D{Mode}
D -->|Count| E["Observe only"]
D -->|Block| F["Drop attack traffic"]
Update: AWS is replacing this feature with the WAF Anti-DDoS managed rule group. Per the AWS Security Blog, auto-upgrade of eligible web ACLs begins October 25, 2026 and automatic mitigation is scheduled to retire January 29, 2027. Verify the current timeline before relying on either.
Take quiz
A second CloudFront distribution
New IAM users
WAF rules in a Shield-managed rule group
The AWS WAF Anti-DDoS managed rule group
AWS Config
Amazon GuardDuty
42. How does Shield Advanced proactive engagement work?
With proactive engagement, the Shield Response Team contacts you first when an attack seems to be hurting your application, instead of waiting for you to notice and open a case.
- Associate a Route 53 health check with the protected resource, one that reflects real application health
- Register your emergency contacts: email, phone number and notes for the on-call person
- Enable proactive engagement in Shield Advanced
- When Shield detects an event and the health check turns unhealthy, the SRT reaches out using those contacts
The health check is the trigger. A check that is too shallow, such as a ping on an unused port, will not fail when the app is really struggling, and the engagement never fires. Keep contacts current, since outdated numbers defeat the point.
Take quiz
A detected event plus an unhealthy Route 53 health check
A scheduled weekly audit
Any 404 response
They are used to bill the subscription
The SRT uses them to reach you during an attack
They set the WAF rule priorities
43. When can you request DDoS cost protection credits?
Credits are not automatic. You can ask for them after a DDoS event raised your usage, provided you meet the conditions:
- The resource was protected by Shield Advanced before the attack (a short lead time is required)
- For CloudFront and ALB, a web ACL with a rate-based rule was associated
- The spike in charges came from scaling on a covered service such as EC2, ELB, CloudFront, Global Accelerator or Route 53
- The event is confirmed as a DDoS attack
You file the claim through AWS Support with the affected resources and time window. The credit covers the extra scaling charges only; the Shield subscription fee and data transfer fees under Shield Advanced still apply. Check the current terms for exact eligibility windows.
Take quiz
Enable S3 versioning
Associate a web ACL with a rate-based rule
Run Inspector scans weekly
Unrelated EBS storage costs
The Shield Advanced subscription fee
Scaling charges caused by the attack
44. How do you enable Shield Advanced protection for a resource?
Shield Advanced is a subscription first, then per-resource protections.
- Subscribe (one-year commitment). In an AWS Organization the fee is $3,000/month for the whole organization.
- Add protection for each resource: CloudFront distribution, Route 53 hosted zone, Global Accelerator, ALB or Classic Load Balancer, or Elastic IP
- Associate a web ACL for L7 coverage, and a Route 53 health check for health-based detection
- Turn on proactive engagement and add emergency contacts
- Optionally grant the SRT access with an IAM role
- Create CloudWatch alarms on the DDoSDetected metric
aws shield create-subscription aws shield create-protection \ --name prod-alb \ --resource-arn arn:aws:elasticloadbalancing:us-east-1:111122223333:loadbalancer/app/prod/abc123
Firewall Manager can apply protections across accounts automatically.
Take quiz
Enable AWS Config rules for S3
Create a VPC peering connection
Subscribe to Shield Advanced
DDoSDetected
VolumeIdleTime
CPUUtilization
45. How does Firewall Manager enforce AWS WAF policies across accounts?
A Firewall Manager administrator account creates an AWS WAF policy that contains the rule groups to enforce, plus a scope: which accounts or OUs, which resource types, and optionally which tags. Firewall Manager then creates or updates a web ACL in each in-scope account.
flowchart TD A["FM admin account: policy"] --> B["Member account 1"] A --> C["Member account 2"] A --> D["New account joins OU"] B --> E["Web ACL with FM rule groups"] C --> F["Web ACL with FM rule groups"] D --> G["Policy applied automatically"]
Firewall Manager owns a first and last set of rule groups in each web ACL. Account owners can add their own rules in the middle. With auto-remediation on, existing resources without protection get the web ACL, and drift is corrected. AWS Config must be enabled in the accounts for Firewall Manager to track resources.
Take quiz
The Firewall Manager administrator account
The Shield Response Team
Each member account independently
Increases the WCU quota
Attaches the policy's protections to non-compliant resources
Deletes unused web ACLs after 30 days
46. How would you design a DDoS-resilient architecture on AWS?
The idea is to absorb attacks at the edge, shrink what is exposed, and scale what remains.
flowchart LR U[Users] --> R53["Route 53"] R53 --> CF["CloudFront + WAF + Shield"] CF --> ALB["ALB in public subnet"] ALB --> ASG["Auto Scaling app tier"] ASG --> DB[(Private database)]
| Layer | What to do |
| Edge | Route 53 and CloudFront absorb floods across many locations; Global Accelerator for non-HTTP |
| Request filtering | WAF with rate-based rules, managed groups and the Anti-DDoS rule group |
| Surface reduction | Lock the ALB to CloudFront using the managed prefix list, keep app and DB tiers private |
| Scale | Auto Scaling and load balancing so legitimate load survives |
| Visibility and response | Shield Advanced, CloudWatch alarms, SRT, tested runbooks |
The weakest link is often an origin reachable directly by IP. If attackers can bypass CloudFront, the edge protection is wasted.
Take quiz
To remove the need for TLS
So attackers cannot bypass the edge and hit the origin directly
To speed up DNS lookups
SQS and SNS
RDS and DynamoDB
Route 53 and CloudFront
47. Explain the execution flow of a request through CloudFront, AWS WAF, and Shield?
In a typical protected setup, traffic passes several checkpoints before your application sees it.
sequenceDiagram
participant C as Client
participant D as Route 53
participant E as CloudFront edge (Shield)
participant W as AWS WAF web ACL
participant O as Origin ALB
C->>D: Resolve domain
D-->>C: Edge IP
C->>E: HTTPS request
E->>E: Shield filters L3/L4 floods
E->>W: Evaluate rules by priority
alt Block
W-->>C: 403 or custom response
else Allow
W->>O: Forward request
O-->>C: Response via CloudFront
end
- DNS resolves to the nearest CloudFront edge, and Route 53 itself is protected by Shield
- Shield filters volumetric and protocol attacks before the request is processed
- The WAF web ACL evaluates rules in priority order and either blocks or lets the request through
- Allowed requests go to the origin, which can run its own regional web ACL
- Logs and metrics are produced for each decision
Take quiz
The WAF default action runs
The origin database rejects it
Shield filters L3/L4 attack traffic at the edge
The client gets a 403 or custom response without the origin seeing it
The origin processes it anyway
CloudFront retries it three times
48. How does managed rule group versioning work in AWS WAF?
Many AWS Managed Rules groups are versioned. By default, your web ACL uses the default version, which AWS updates over time as it adds or tunes rules. That keeps you current, but a rule change can occasionally affect traffic that used to pass.
You can instead pin a static version. The behavior stays frozen until you move it yourself, which gives you a controlled upgrade path.
- Subscribe to the managed rule group's SNS notifications, so you hear about new versions and updates
- Create a test web ACL (or a duplicate rule) pointing at the new version, with actions overridden to Count
- Compare matches to the current version using logs
- Switch production to the new version when it looks safe
Static versions do not last forever. AWS eventually retires old ones, so pinning is a delay tactic, not a permanent setting.
Take quiz
Frozen rule behavior until you choose to upgrade
Automatic updates every day
Free usage of all paid groups
Switch production immediately
Test it in Count mode against real traffic first
Delete the old version
49. How can you optimize AWS WAF cost?
WAF cost is mostly requests, rules and extras. Know the pricing parts first: a monthly fee per web ACL ($5), a monthly fee per rule or rule group ($1 each), a per-million-request charge, and add-ons for WCUs beyond 1,500, larger body inspection and the intelligent threat groups.
- Share one web ACL across many resources where the rules fit; the web ACL fee is per ACL
- Scope down Bot Control, ATP, ACFP and Anti-DDoS to the paths that need them
- Order rules so cheap Allow and Block rules (IP sets, geo) run before expensive inspection
- Replace many IP rules with a single IP set and avoid regex pattern sets (25 WCUs)
- Keep body inspection at the default unless you truly need more
- Use logging filters to avoid storing every allowed request
- If you run Shield Advanced, use the WAF fee waiver on protected resources
Always check the current price list. Rates change by Region and feature.
Take quiz
Regex pattern set match
IP set match
Bot Control targeted level
Enabling full body logging
Logging to three destinations at once
A logging filter that drops most allowed requests
50. How do you manage AWS WAF configuration as code?
Treat the web ACL like application code: define it in CloudFormation, Terraform or CDK, review it in pull requests and deploy it through a pipeline.
Resources: AppWebAcl: Type: AWS::WAFv2::WebACL Properties: Scope: REGIONAL DefaultAction: { Allow: {} } VisibilityConfig: SampledRequestsEnabled: true CloudWatchMetricsEnabled: true MetricName: AppWebAcl Rules: - Name: CommonRules Priority: 10 OverrideAction: { None: {} } Statement: ManagedRuleGroupStatement: { VendorName: AWS, Name: AWSManagedRulesCommonRuleSet } VisibilityConfig: SampledRequestsEnabled: true CloudWatchMetricsEnabled: true MetricName: CommonRules
- Keep IP sets and custom rule groups as separate resources so they can be updated alone
- Size rule group capacity carefully, since changing it forces a replacement
- Ship new rules in Count first, then promote to Block in a later commit
- Use drift detection, and remember Firewall Manager or Shield changes can alter a web ACL outside your template