Protect Web App from SQL Injection and XSS with AWS WAF and Shield Advanced
A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting. Which AWS service should they use?
⚠ Common exam trap
Watch out — candidates often confuse AWS WAF with AWS Network Firewall, thinking network-layer filtering is sufficient for application-layer threats, but WAF is specifically designed for HTTP/HTTPS inspection at the application layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF
AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). It integrates directly with Application Load Balancers to inspect HTTP/HTTPS requests and block malicious traffic based on customizable rules. This makes it the correct choice for the security team's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Network Firewall
Why it's wrong here
AWS Network Firewall filters traffic at the network and transport layers using stateless and stateful rule groups, and it provides intrusion prevention for VPCs through Suricata-compatible rules. However, it does not perform web-application-aware inspection of HTTP request bodies and headers to block SQL injection or XSS; those attacks require understanding of application semantics. Thus, it is not the correct service for this application-layer protection need.
- ✓
AWS WAF
Why this is correct
AWS WAF is a web application firewall that protects web applications by inspecting HTTP(S) requests and allowing or blocking them based on rules you define. It specifically includes managed rule groups and match conditions for SQL injection and cross-site scripting (XSS), as well as rate-based rules to mitigate abusive traffic. Since the application is running in EC2 behind an Application Load Balancer or Amazon CloudFront, AWS WAF can be attached to those endpoints directly.
- ✗
AWS Firewall Manager
Why it's wrong here
AWS Firewall Manager is a central security management service that enforces security policies across accounts in an AWS Organization, including policies for AWS WAF, AWS Shield Advanced, and VPC security groups. It automates the deployment and maintenance of rules, but it is not an inspection engine and does not block SQL injection or XSS by itself. The company would still need AWS WAF as the actual protective layer; Firewall Manager could only manage its configuration centrally.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced provides always-on DDoS protection against large volumetric and state-exhaustion attacks at the network and transport layers, and it can be combined with AWS WAF for application-layer attack mitigation. However, it does not inspect individual HTTP requests for malicious patterns like SQL commands or cross-site scripting payloads. Therefore, Shield Advanced alone would not prevent these specific web exploits.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.