Skip to content
BytePatterns

SCS-C03 · Domain 3: Infrastructure Security · 18% of the exam

Task 3.1: Design, implement, and troubleshoot security controls for network edge services

Stopping attacks at the edge: AWS WAF rules against the OWASP Top 10, rate limits, geographic rules and client fingerprints, CloudFront headers and origin protection, S3 CORS, IoT policies, Shield Advanced, and edge data shared with other tools.

Study it

  • AWS WAF: managed rule groups, OWASP Top 10, geographic rules and fingerprints

    Lesson coming

  • Rate limiting at the edge: rate-based rules

    Partly covered by: Rate Limiting

  • CloudFront security: origin access control, headers, signed URLs and S3 CORS

    Partly covered by: CloudFront & Caching Layers

  • DDoS protection: Shield Standard and Shield Advanced

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A web application runs behind an Application Load Balancer that has an AWS WAF web ACL. All traffic reaches the load balancer through a partner's content delivery network, which adds the original client IP address in the X-Forwarded-For header. The security team must limit each client to 100 requests in 5 minutes on the /login path only. Which AWS WAF configuration meets this requirement?

  1. AA rate-based rule keyed on the source IP address, scoped down to the /login path
  2. BA rate-based rule keyed on the forwarded IP in a header, scoped down to /login
  3. CAn IP set match rule that blocks addresses taken from recent login failure logs
  4. DThe AWS managed Amazon IP reputation list rule group set to block
Show the answer and why
  • AA rate-based rule keyed on the source IP address, scoped down to the /login path

    Incorrect

    Behind a proxy, the source IP is the address of the last proxy, so many clients would share a few counters and be throttled together.

  • BA rate-based rule keyed on the forwarded IP in a header, scoped down to /login

    Correct

    Aggregating on a forwarded IP address counts each original client, and the scope-down statement limits counting to the login path.

  • CAn IP set match rule that blocks addresses taken from recent login failure logs

    Incorrect

    A static block list reacts after the fact and does not enforce a per-client request rate.

  • DThe AWS managed Amazon IP reputation list rule group set to block

    Incorrect

    IP reputation lists block known bad sources. They do not limit how often each client can call the login path.

Rate limits are only as good as the key they count by. Behind a CDN or proxy, count by the forwarded IP, and remember that headers can be spoofed, so pair it with other controls.

Question 2 · choose 2

A CloudFront distribution serves objects from an S3 bucket. The objects are encrypted with SSE-KMS using a customer managed key. Users must not be able to read the objects directly from S3, only through this distribution. Which configuration steps are needed? (Choose TWO.)

  1. AUse an origin access identity (OAI) and grant it s3:GetObject in the bucket policy
  2. BUse origin access control and a bucket policy for cloudfront.amazonaws.com with AWS:SourceArn
  3. CLet cloudfront.amazonaws.com decrypt in the KMS key policy, scoped with AWS:SourceArn
  4. DConfigure the bucket as a static website endpoint and use it as a custom origin for the distribution
  5. ERequire viewers to use CloudFront signed URLs created with a trusted key group
Show the answer and why
  • AUse an origin access identity (OAI) and grant it s3:GetObject in the bucket policy

    Incorrect

    OAI does not support SSE-KMS, or needs workarounds for it. AWS recommends origin access control instead.

  • BUse origin access control and a bucket policy for cloudfront.amazonaws.com with AWS:SourceArn

    Correct

    OAC signs requests to S3, and the bucket policy admits only the CloudFront service principal acting for this distribution.

  • CLet cloudfront.amazonaws.com decrypt in the KMS key policy, scoped with AWS:SourceArn

    Correct

    With SSE-KMS, the distribution also needs permission to decrypt with the key, granted in the key policy and scoped to the distribution.

  • DConfigure the bucket as a static website endpoint and use it as a custom origin for the distribution

    Incorrect

    A website endpoint must be set up as a custom origin, and then OAC cannot be used, so direct access cannot be restricted this way.

  • ERequire viewers to use CloudFront signed URLs created with a trusted key group

    Incorrect

    Signed URLs control which viewers can fetch content through CloudFront. They do not stop direct requests to the bucket.

Two policies have to admit CloudFront: the bucket policy, for the request, and the key policy, for decryption. Both scope the service principal to the one distribution with AWS:SourceArn.

Question 3 · choose 1

A CloudFront distribution with an AWS WAF web ACL serves a public website and an administration area under /admin/. The public site must stay available worldwide, but requests to /admin/ from any country other than the United States must be blocked. What should the security team do?

  1. ACloudFront geographic restrictions with an allow list that contains only the United States
  2. BA web ACL rule that blocks every request that does not match a United States geo match
  3. CA web ACL rule that blocks /admin/ requests that do not match a United States geo match
  4. DA rate-based rule for /admin/ with a scope-down geo match for countries outside the United States
Show the answer and why
  • ACloudFront geographic restrictions with an allow list that contains only the United States

    Incorrect

    Geographic restrictions apply to the entire distribution, so the public site would be blocked outside the United States as well.

  • BA web ACL rule that blocks every request that does not match a United States geo match

    Incorrect

    Without a path condition, the rule blocks every non-US request, including the public site.

  • CA web ACL rule that blocks /admin/ requests that do not match a United States geo match

    Correct

    Combining a path match with a negated geo match blocks only the admin area for requests from other countries.

  • DA rate-based rule for /admin/ with a scope-down geo match for countries outside the United States

    Incorrect

    A rate-based rule only blocks clients above a request rate; slow requests from other countries would still reach the admin area.

CloudFront geographic restrictions work at distribution level only. For one part of a site, combine an AWS WAF geo match with a path condition.

Question 4 · choose 1

A company runs a public web application on an Application Load Balancer. Its threat model lists cross-site scripting and SQL injection in query strings, cookies and request bodies. The team wants coverage for these threats with the least rule-writing and maintenance effort. What should the team do?

  1. AAn AWS WAF web ACL with the AWS managed core rule set and SQL database rule groups
  2. BAWS Shield Advanced protection for the load balancer with proactive engagement
  3. CSecurity group rules on the load balancer that allow only known client IP ranges
  4. DAn AWS WAF web ACL with the AWS managed Amazon IP reputation list rule group
Show the answer and why
  • AAn AWS WAF web ACL with the AWS managed core rule set and SQL database rule groups

    Correct

    The core rule set covers common web exploits from the OWASP publications, and the SQL database group targets SQL injection; AWS maintains both.

  • BAWS Shield Advanced protection for the load balancer with proactive engagement

    Incorrect

    Shield Advanced focuses on DDoS protection. It does not inspect requests for injection payloads unless web ACL rules do so.

  • CSecurity group rules on the load balancer that allow only known client IP ranges

    Incorrect

    Security groups filter by address and port. They do not inspect HTTP requests, and a public API cannot list its clients.

  • DAn AWS WAF web ACL with the AWS managed Amazon IP reputation list rule group

    Incorrect

    The reputation list blocks known bad sources; it does not inspect request contents for XSS or SQL injection.

Managed rule groups are how AWS WAF covers the OWASP-style application threats without hand-written rules: start in count mode, review, then block.

Question 5 · choose 1

A startup runs a website on CloudFront and has no budget for extra DDoS services. What protection against common network and transport layer DDoS attacks does it already have?

  1. ANone, until AWS Shield Advanced is subscribed
  2. BAWS Shield Standard, at no additional charge
  3. COnly protection from AWS WAF rate-based rules
  4. DOnly protection from the Shield Response Team
Show the answer and why
  • ANone, until AWS Shield Advanced is subscribed

    Incorrect

    Shield Standard protects every AWS customer automatically.

  • BAWS Shield Standard, at no additional charge

    Correct

    All AWS customers get Shield Standard's automatic protection against the most common network and transport layer attacks.

  • COnly protection from AWS WAF rate-based rules

    Incorrect

    WAF rules are not deployed by default and work at the application layer.

  • DOnly protection from the Shield Response Team

    Incorrect

    Shield Response Team access is part of Shield Advanced.

Shield Advanced adds application layer coverage, cost protection and response support for workloads that need them.

Question 6 · choose 1

A security team has a list of 300 IP addresses that must be blocked from reaching an application behind an AWS WAF protection pack (web ACL). The list changes every week. What is the simplest way to manage this?

  1. AOne rule per IP address in the protection pack
  2. BA security group rule that denies the addresses
  3. CAn IP set referenced by a block rule
  4. DA rate-based rule with a low request limit
Show the answer and why
  • AOne rule per IP address in the protection pack

    Incorrect

    Hundreds of separate rules are hard to maintain and change weekly.

  • BA security group rule that denies the addresses

    Incorrect

    Security groups have no deny rules.

  • CAn IP set referenced by a block rule

    Correct

    An IP set holds the addresses in one place; a rule that references it blocks them, and only the set needs updating.

  • DA rate-based rule with a low request limit

    Incorrect

    Rate-based rules react to request rates, not to a fixed address list.

Updating the IP set does not require changing the rule that uses it.

Question 7 · choose 1

A public REST API in API Gateway must reject all requests that do not come from the company's office IP range, before any backend runs. The team wants no code. What should it use?

  1. AA Lambda authorizer that checks the caller's IP address
  2. BA usage plan with an API key for the office
  3. CA resource policy that denies other source IP ranges
  4. DCORS settings that allow only the office domain
Show the answer and why
  • AA Lambda authorizer that checks the caller's IP address

    Incorrect

    An authorizer is code that the team wants to avoid.

  • BA usage plan with an API key for the office

    Incorrect

    API keys are not an access control mechanism.

  • CA resource policy that denies other source IP ranges

    Correct

    API Gateway resource policies can deny traffic based on source IP address or range.

  • DCORS settings that allow only the office domain

    Incorrect

    CORS guides browsers; it does not block other clients.

Resource policies are evaluated by API Gateway itself, so blocked requests never reach the integration.

Question 8 · choose 1

A bank wants DNS resolvers to be able to verify that answers for its public domain in Route 53 really come from Route 53 and were not tampered with. What should it turn on?

  1. ADNSSEC signing for the public hosted zone
  2. BRoute 53 Resolver DNS Firewall rules in the VPC
  3. CPublic DNS query logging for the hosted zone
  4. DHealth checks on the zone's records
Show the answer and why
  • ADNSSEC signing for the public hosted zone

    Correct

    DNSSEC signing lets resolvers validate that responses came from Route 53 and were not changed.

  • BRoute 53 Resolver DNS Firewall rules in the VPC

    Incorrect

    DNS Firewall filters queries from your VPCs, not answers for your public domain.

  • CPublic DNS query logging for the hosted zone

    Incorrect

    Query logging records queries; it does not authenticate answers.

  • DHealth checks on the zone's records

    Incorrect

    Health checks test endpoints, not the integrity of DNS answers.

DNSSEC also needs the chain of trust at the parent domain through a DS record.

Question 9 · choose 1

A penetration test warns that an Application Load Balancer forwards requests that might pose an HTTP desync risk. Which load balancer attribute controls how such requests are handled?

  1. Arouting.http.xff_header_processing.mode
  2. Bdeletion_protection.enabled
  3. Cwaf.fail_open.enabled
  4. Drouting.http.desync_mitigation_mode
Show the answer and why
  • Arouting.http.xff_header_processing.mode

    Incorrect

    This sets how the load balancer handles the X-Forwarded-For header.

  • Bdeletion_protection.enabled

    Incorrect

    Deletion protection stops the load balancer from being deleted.

  • Cwaf.fail_open.enabled

    Incorrect

    This decides what happens when AWS WAF cannot be reached.

  • Drouting.http.desync_mitigation_mode

    Correct

    This attribute sets how the load balancer handles requests that might pose a desync risk, with monitor, defensive and strictest modes.

The defensive default suits most applications; strictest blocks any request that does not comply with the HTTP standard.

Practise domain 3 →Practise all domains →