Question 1 · choose 1
A web application runs behind an Application Load Balancer that has an AWS WAF web ACL. All traffic reaches the load balancer through a partner's content delivery network, which adds the original client IP address in the X-Forwarded-For header. The security team must limit each client to 100 requests in 5 minutes on the /login path only. Which AWS WAF configuration meets this requirement?
- AA rate-based rule keyed on the source IP address, scoped down to the /login path
- BA rate-based rule keyed on the forwarded IP in a header, scoped down to /login
- CAn IP set match rule that blocks addresses taken from recent login failure logs
- DThe AWS managed Amazon IP reputation list rule group set to block
Show the answer and why
AA rate-based rule keyed on the source IP address, scoped down to the /login path
Incorrect
Behind a proxy, the source IP is the address of the last proxy, so many clients would share a few counters and be throttled together.
BA rate-based rule keyed on the forwarded IP in a header, scoped down to /login
Correct
Aggregating on a forwarded IP address counts each original client, and the scope-down statement limits counting to the login path.
CAn IP set match rule that blocks addresses taken from recent login failure logs
Incorrect
A static block list reacts after the fact and does not enforce a per-client request rate.
DThe AWS managed Amazon IP reputation list rule group set to block
Incorrect
IP reputation lists block known bad sources. They do not limit how often each client can call the login path.
Rate limits are only as good as the key they count by. Behind a CDN or proxy, count by the forwarded IP, and remember that headers can be spoofed, so pair it with other controls.
AWS documentation