SCS-C02 Infrastructure Security Practice Question
A security engineer is configuring AWS WAF to protect an Application Load Balancer (ALB) from SQL injection attacks. The engineer must ensure that only requests with a specific header are allowed and that SQL injection attempts are blocked. Which combination of AWS WAF components should the engineer use?
⚠ Common exam trap
A common mix-up: candidates confuse count and block actions, or assuming that a rate-based rule or regex pattern set can replace the dedicated SQL injection match condition and header check.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A web ACL with a rule that blocks requests missing the required header, and a rule that uses the SQL injection match condition to block malicious requests.
AWS WAF web ACLs can contain multiple rules. To enforce a required header, a rule that blocks requests missing that header is needed. To block SQL injection, the built-in SQL injection match condition is the appropriate choice. Combining these two rules in a web ACL associated with the ALB meets both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A web ACL with a rule that blocks requests missing the required header, and a rule that uses the SQL injection match condition to block malicious requests.
Why this is correct
AWS WAF web ACLs contain rules that can inspect headers and use match conditions like SQL injection. A rule to block requests missing the header enforces the header requirement, and a SQL injection match condition blocks malicious payloads. Both can be combined in a single web ACL associated with the ALB.
- ✗
A web ACL with a rule that allows requests with the header and a rule that uses the SQL injection match condition to count malicious requests.
Why it's wrong here
Using a count action for SQL injection does not block the requests; it only logs them. The requirement is to block SQL injection attempts. Additionally, an allow rule for the header does not block requests missing it, so the header requirement is not enforced.
- ✗
A web ACL with a rule that blocks requests missing the header, and a rule that uses a regex pattern set to block SQL injection attempts.
Why it's wrong here
While a regex pattern set can detect some SQL injection patterns, AWS WAF provides a dedicated SQL injection match condition that is more robust and easier to maintain. Using regex for SQL injection is error-prone and not the recommended approach, though it could work in limited cases.
- ✗
A web ACL with a rate-based rule to limit requests and a rule that uses the SQL injection match condition to block malicious requests.
Why it's wrong here
A rate-based rule limits request volume but does not enforce the presence of a specific header. The requirement to allow only requests with a specific header is not met by rate limiting. The SQL injection rule is correct, but the header enforcement is missing.
Visual reference
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.