Question 1 · choose 1
An online store runs behind an Application Load Balancer. It wants to block HTTP requests that try to inject SQL commands through its search form before they reach the application. Which service should it use?
- AAWS Shield
- BAmazon GuardDuty
- CAmazon Inspector
- DAWS WAF
Show the answer and why
AAWS Shield
Incorrect
Shield protects against distributed denial of service (DDoS) attacks. It does not inspect requests for SQL injection.
BAmazon GuardDuty
Incorrect
GuardDuty is a threat detection service that analyzes logs and raises findings. It does not sit in front of the load balancer filtering requests.
CAmazon Inspector
Incorrect
Inspector scans workloads for software vulnerabilities and unintended network exposure. It does not block incoming requests.
DAWS WAF
Correct
AWS WAF is a web application firewall for HTTP(S) requests to resources such as an Application Load Balancer, and its SQL database managed rule group blocks request patterns associated with SQL injection.
Filtering individual web requests by what they contain is a web application firewall's job. Shield handles floods of traffic; GuardDuty and Inspector detect and report rather than block.
AWS documentation