SCS-C02 Infrastructure Security Practice Question
A company is using AWS WAF to protect its Application Load Balancer (ALB). The security team wants to block requests that do not contain a valid API key in the HTTP header 'X-API-Key'. Which WAF rule type should be used?
⚠ Common exam trap
Test-takers frequently confuse string match conditions with regex pattern sets, assuming that a simple 'contains' or 'starts with' string match is sufficient for validating structured data like API keys, when in fact regex provides the necessary pattern flexibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regex pattern set
A regex pattern set rule is the correct choice because it allows you to define a regular expression pattern that matches the expected format of valid API keys in the 'X-API-Key' header. AWS WAF regex pattern sets can be used in a rule to inspect the header value and block requests that do not match the pattern, providing flexible and precise validation beyond simple string matching.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
String match condition
Why it's wrong here
A string match condition in AWS WAF performs exact string or substring matching on a specified request component, such as a header or query parameter. Because it does not support regex metacharacters, it cannot express the set of all valid API key formats; you would have to list every possible key individually, which is impractical and insecure. Therefore, it is unsuitable for validating whether an API key conforms to a pattern and blocking invalid ones.
- ✓
Regex pattern set
Why this is correct
A regex pattern set lets you define a regular expression that describes the structural format of valid API keys, such as a required prefix followed by a specific number of alphanumeric characters. In a WAF rule, you can use the 'not' operator to inspect the API key header and block any request whose key does not match this pattern, providing centralized pattern-based validation at the edge. This directly addresses the requirement to reject invalid API keys.
- ✗
Rate-based rule
Why it's wrong here
A rate-based rule tracks the number of requests from a given source IP address over a rolling window and blocks traffic that exceeds a configured threshold. It is designed to mitigate DDoS attacks and aggressive bots, but it never inspects the content or format of an API key. Thus, an attacker could send a low volume of requests with invalid keys and still pass through the rate-based rule, so it cannot implement API key validation.
- ✗
IP set
Why it's wrong here
An IP set is a collection of IP addresses or CIDR ranges that can be referenced in a WAF rule to allow or block traffic based solely on the network source address. It does not have any visibility into application-layer fields like the API key header, and an attacker can easily spoof or rotate IPs to bypass IP-based filtering. This makes it irrelevant for validating the authenticity of API keys presented in request headers.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.