SCS-C02 Infrastructure Security Practice Question
A company has a web application running on EC2 instances behind an Application Load Balancer (ALB). The application uses a custom header X-Auth-Token to authenticate requests. The security team wants to use AWS WAF to block requests that do not contain this header or contain an invalid token. The WAF is associated with the ALB. The team creates a rule with a match condition that checks for the presence of the X-Auth-Token header and a regex pattern for the token value. However, the rule is not blocking any requests. What is the most likely cause?
⚠ Common exam trap
SCS-C02 often tests the misconception that AWS WAF cannot inspect custom headers or that rule order doesn't matter; candidates must remember that rule priority and action determine whether a block rule is ever reached.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
There is an allow rule with a higher priority that allows all requests before the block rule is evaluated.
AWS WAF evaluates rules in priority order, and the first rule that matches determines the action. If an allow rule with a lower number (higher priority) matches all requests, the block rule is never evaluated. Therefore, the most likely cause is that an allow rule with higher priority is permitting all traffic before the block rule can inspect the header.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS WAF is not supported for Application Load Balancers; it only supports CloudFront.
Why it's wrong here
AWS WAF does support Application Load Balancers; in fact, ALB is one of the primary resource types you can associate a web ACL with, alongside Amazon CloudFront and AWS AppSync. The statement that WAF is only for CloudFront is factually incorrect, so the block rule not taking effect cannot be attributed to a lack of ALB support. WAF fully integrates with ALB and can apply managed or custom rules to incoming HTTP(S) requests.
- ✗
AWS WAF cannot inspect custom headers; it can only inspect standard HTTP headers.
Why it's wrong here
AWS WAF can inspect custom request headers, not just standard HTTP headers. You can create rule conditions that match on any header name—including proprietary token headers—using string match, regex patterns, or size constraints. Therefore, the inability to inspect custom headers is not the reason the block rule is being bypassed; WAF is fully capable of parsing and matching on custom header values.
- ✗
The regex pattern for the token is too complex for AWS WAF to process.
Why it's wrong here
AWS WAF supports regex patterns and will process them accurately, provided they conform to the service quotas (e.g., default 10 regex patterns per pattern set, 512 KB per set). A typical token validation regex is well within these limits, so complexity alone would not prevent evaluation. The actual cause of a block rule being skipped is almost always related to rule priority, not the regex engine's capability.
- ✓
There is an allow rule with a higher priority that allows all requests before the block rule is evaluated.
Why this is correct
AWS WAF evaluates rules in ascending priority order, where lower numeric priority values are evaluated first. If a higher-priority allow rule (e.g., priority 0) matches all requests and is set to 'Allow', the web ACL immediately stops evaluating remaining rules, so a lower-priority block rule (e.g., priority 1) is never reached. The presence of such a broad allow rule fully explains why requests are not blocked, even when the block rule itself is properly configured.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.