Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company uses AWS WAF to protect its web application from common web exploits. The security team wants to block requests that contain SQL injection or cross-site scripting (XSS) in the query string. Which rule type should be used?

⚠ Common exam trap

Many candidates think custom regex rules are necessary for precise control, but AWS WAF managed rule groups are specifically designed to handle SQL injection and XSS with higher accuracy and lower maintenance, making them the recommended choice for this use case.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Managed rule group for SQL injection and XSS

AWS WAF managed rule groups, such as the AWS-AWSManagedRulesSQLiRuleSet and AWS-AWSManagedRulesXSSRuleSet, are pre-configured to inspect query strings for SQL injection and cross-site scripting (XSS) patterns. Using a managed rule group is the most efficient and accurate approach because it leverages AWS's continuously updated threat signatures, reducing false positives and administrative overhead compared to custom rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Custom regex pattern set

    Why it's wrong here

    A custom regex pattern set lacks the contextual analysis of SQL injection and XSS payloads that AWS WAF’s managed SQL injection and XSS rule groups provide; regex can only match literal string patterns, so it cannot detect encoded, obfuscated, or variant attack vectors that bypass static signatures. It is tempting because regex offers flexibility for blocking arbitrary patterns in query strings, and would be correct for blocking a known, fixed string like `DROP TABLE` that does not require contextual decoding.

  • ✓

    Managed rule group for SQL injection and XSS

    Why this is correct

    AWS WAF managed rule groups such as AWSManagedRulesSQLiRuleSet and AWSManagedRulesCommonRuleSet are purpose-built to detect SQL injection (SQLi) and cross-site scripting (XSS) using context-aware inspection that decodes and normalizes the request. Unlike simple regex matching, these rule groups apply heuristic and signature-based analysis that catches encoded payloads, comment obfuscation, and case variations, and AWS continuously updates them to address new evasion techniques, making them the appropriate, low-maintenance solution for this threat.

  • ✗

    Rate-based rule

    Why it's wrong here

    A rate-based rule tracks the number of requests from a single client IP within a configurable time window and triggers an action once the count exceeds a set threshold, which is ideal for mitigating volumetric attacks like credential stuffing, account takeover, or layer 7 DDoS. It does not inspect the content of the request body or query string, so although it might incidentally slow down an automated attack, it cannot distinguish a benign request from those containing SQL injection or XSS payloads.

  • ✗

    Geographic match rule

    Why it's wrong here

    A geographic match rule evaluates the country of origin of the requesting IP address and applies an allow or block action based on that location, typically used for regional compliance or to block traffic from high-risk areas. This rule never examines the request payload or parameters, so it provides no detection capability for SQL injection or XSS; an attacker in a permitted country can still exploit the vulnerability, and a blocked malicious request is blocked only because of its origin, not its content.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.