passdrill
AWS SAA-C03 · IAM & Security · Card 012/014 easy

A public-facing web application behind an Application Load Balancer is being probed with SQL injection attempts inside request bodies. The team wants to inspect and block malicious requests based on their HTTP content before they reach the application, without changing application code. Which service should they attach to the load balancer?

  1. Amazon GuardDuty, attached directly to the ALB to inspect request payloads
  2. AWS Shield Advanced, configured with a custom Layer 7 payload-inspection rule
  3. AWS WAF, associated with the ALB through a web ACL containing a rule that matches SQL injection patterns
  4. Security groups on the ALB, adding an inbound rule that denies traffic containing SQL keywords
Next card → Shuffle