SCS-C02 Infrastructure Security Practice Question
A company's security engineer is configuring a web application firewall (WAF) to protect a public-facing Application Load Balancer (ALB). The application is vulnerable to SQL injection attacks. Which AWS WAF rule should be used to mitigate this threat?
⚠ Common exam trap
A common mix-up: candidates confuse SQL injection with XSS because both involve input validation, but AWS WAF treats them as distinct managed rule groups with separate inspection logic and signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a rule from the AWS Managed Rules for SQL injection.
AWS WAF includes managed rule groups specifically designed to detect and block SQL injection attacks by inspecting request parameters, URIs, and headers for malicious SQL patterns. This directly addresses the vulnerability described in the scenario, as SQL injection targets the application's database layer through crafted input.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a rule to block cross-site scripting (XSS) attacks.
Why it's wrong here
Cross-site scripting (XSS) and SQL injection are distinct vulnerability classes: XSS injects client-side script into web pages, while SQL injection manipulates backend database queries. AWS WAF offers separate managed rule groups for each, and the XSS detection rules will not match SQLi payloads like UNION SELECT or OR 1=1. Adding an XSS-specific rule would therefore leave the SQLi attack path unaffected.
- ✓
Add a rule from the AWS Managed Rules for SQL injection.
Why this is correct
AWS WAF's AWSManagedRulesSQLiRuleSet is a managed rule group specifically designed to detect and block SQL injection attempts by inspecting request components such as query strings, body, and headers. It uses curated signatures and pattern-matching to catch syntactic SQLi payloads, and you can associate it with your web ACL on the Application Load Balancer, CloudFront, or API Gateway. Enabling this rule directly addresses the reported vulnerability.
- ✗
Add a rate-based rule to limit requests per IP.
Why it's wrong here
A rate-based rule imposes a cap on the number of requests from a single IP address over a fixed time window, typically to mitigate brute-force or DDoS-style high-volume attacks. SQL injection is often executed in a single, carefully crafted request, or via low-volume targeted attempts, so an attacker can easily stay under the rate threshold. Therefore, this control does not inspect request content and would not block the SQLi payload.
- ✗
Add a geographic match rule to block traffic from specific countries.
Why it's wrong here
A geographic match rule allows or blocks requests based on the country derived from the request's source IP, commonly used to restrict access to certain regions. It operates entirely on geolocation metadata and performs no content inspection, so it cannot differentiate benign requests from SQLi patterns. Since SQL injection can originate from any geographic area, including the company's own country, geo-blocking is not a valid countermeasure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.