Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company uses AWS WAF to protect a web application. The security team wants to block requests that contain SQL injection patterns. Which WAF rule type should be used?

⚠ Common exam trap

Watch out — candidates often confuse a rate-based rule (which controls request volume) with a content-based rule (which inspects payloads), leading them to pick Option C instead of the correct SQL injection match rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection match rule

AWS WAF provides a dedicated SQL injection match rule that inspects incoming requests for SQL injection patterns in the URI, query string, or body. This rule uses a set of predefined SQL-like patterns (e.g., 'OR 1=1', 'UNION SELECT') to detect and block malicious input, directly addressing the security team's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IP set rule

    Why it's wrong here

    An IP set rule in AWS WAF matches requests solely against a defined list of IPv4/IPv6 addresses or CIDR ranges, and it cannot inspect the HTTP body, query string, or header content for malicious patterns. SQL injection is a payload-level attack that arrives in legitimate-looking requests from any source address, so an IP-based blocklist or allowlist has no visibility into the presence of SQL keywords or metacharacters in the request. Even if an attacker's IP is unknown or changed via proxies, an IP set rule will never evaluate the request parameters, making it ineffective for detecting SQLi.

  • ✗

    Geographic match rule

    Why it's wrong here

    A geographic match rule filters traffic based on the country or region derived from the requesting IP address's geo-location, triggering an action for entire geo categories such as 'block all traffic from Country X'. SQL injection attack payloads can be sent from any country, including the same country as legitimate users, so geography provides no signal about the actual request content. This rule type operates at the network-origin layer, not the application layer, and therefore cannot identify SQL injection signatures hidden in input fields.

  • ✗

    Rate-based rule

    Why it's wrong here

    A rate-based rule in AWS WAF tracks the number of requests from a given source IP within a rolling five-minute window and triggers an action when the count exceeds a specified threshold, making it effective for throttling high-volume attacks like DDoS or brute-force login attempts. It does not inspect the content of any individual request, so a single low-volume SQL injection attempt will never approach the rate threshold and will pass through undetected. Its decision logic is purely statistical and time-dependent, not signature- or pattern-based, which is why it cannot detect a focused SQLi probe.

  • ✓

    SQL injection match rule

    Why this is correct

    An SQL injection match rule in AWS WAF inspects the request components you configure—such as the query string, body, header, or cookie values—for known SQLi signatures like ' OR '1'='1, UNION SELECT, or comment and quote sequences. It uses pattern matching, optionally normalized with rule-specific text transformations to reduce evasive bypasses like URL encoding or case variation. This is the only rule type among the options that performs payload-level content inspection and produces a match based on the actual malicious input in the request, making it the correct choice for detecting SQL injection.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.