SCS-C02 Infrastructure Security Practice Question
A company uses AWS Shield Advanced to protect its web application against DDoS attacks. The application is behind an Application Load Balancer (ALB) with a web application firewall (AWS WAF) in front. The security team notices that some requests are being blocked by AWS WAF, but the source IP addresses are legitimate customers. What step should the team take to minimize false positives?
⚠ Common exam trap
SCS-C02 often tests the misconception that increasing thresholds or using managed rules directly solves false positives, but the key is to first monitor with count mode to gather data before making blocking decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement rate-based rules with a count action and use the count data to create custom rules.
Rate-based rules with a count action allow the team to monitor request patterns without blocking legitimate traffic. The count action logs matching requests, enabling analysis to create custom rules that accurately distinguish between malicious and legitimate traffic. This approach minimizes false positives by basing rule logic on observed data rather than static thresholds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement rate-based rules with a count action and use the count data to create custom rules.
Why this is correct
Use a rate-based rule in COUNT mode so WAF evaluates the request rate and increments the relevant counters without blocking traffic. This exposes the per-IP distribution in CloudWatch metrics and sampled requests, letting you determine a burst threshold that separates human usage from automated floods. The count data then informs a custom rule (e.g., with an aggregate key or scope-down statement) that blocks only when the observed rate genuinely exceeds your normal baseline, minimizing false positives.
- ✗
Switch to using AWS Managed Rules for IP reputation lists.
Why it's wrong here
AWS Managed Rules for IP reputation lists contain threat-intelligence ranges from third-party sources and block requests solely on IP address reputation, not on the actual request characteristics or your application's traffic profile. A legitimate user who happens to share an IP range with known abuse (e.g., a NAT egress or a cloud provider block) will still be blocked, making it a poor substitute for an application-aware rate limit. Additionally, managed IP lists are static between updates and don't adapt to your baseline, whereas a count-based custom rule can be tuned with your own metrics.
- ✗
Increase the WAF rate-based rule threshold to allow more requests.
Why it's wrong here
Simply raising the rate-based threshold widens the bandwidth of allowed requests, so while it may reduce false positives, it also lets more attack traffic pass under the ceiling. The correct approach is to first quantify normal traffic with count mode and then set the threshold at a statistically defensible point above that baseline. Without this data, any threshold increase is arbitrary and can leave the application more exposed to a distributed burst that your original threshold would have stopped.
- ✗
Reconfigure the ALB idle timeout to a higher value.
Why it's wrong here
The ALB idle timeout governs how long the load balancer keeps an HTTP connection open after the last request; it has no bearing on how WAF inspects requests, nor on the per-IP rate counters that feed a rate-based rule. Changing this setting does not alter whether a request is considered part of a burst or whether it matches an IP reputation block, so it cannot mitigate false positives. The WAF engine evaluates traffic before the ALB forwards it, so request-level blocking decisions are unaffected by connection timeout values.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.