Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A security engineer is configuring AWS WAF to protect an Application Load Balancer (ALB) from SQL injection attacks. The engineer must ensure that only requests with a specific header are allowed and that SQL injection attempts are blocked. Which combination of AWS WAF components should the engineer use?

⚠ Common exam trap

A common mix-up: candidates confuse count and block actions, or assuming that a rate-based rule or regex pattern set can replace the dedicated SQL injection match condition and header check.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A web ACL with a rule that blocks requests missing the required header, and a rule that uses the SQL injection match condition to block malicious requests.

AWS WAF web ACLs can contain multiple rules. To enforce a required header, a rule that blocks requests missing that header is needed. To block SQL injection, the built-in SQL injection match condition is the appropriate choice. Combining these two rules in a web ACL associated with the ALB meets both requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A web ACL with a rule that blocks requests missing the required header, and a rule that uses the SQL injection match condition to block malicious requests.

    Why this is correct

    AWS WAF web ACLs contain rules that can inspect headers and use match conditions like SQL injection. A rule to block requests missing the header enforces the header requirement, and a SQL injection match condition blocks malicious payloads. Both can be combined in a single web ACL associated with the ALB.

  • ✗

    A web ACL with a rule that allows requests with the header and a rule that uses the SQL injection match condition to count malicious requests.

    Why it's wrong here

    Using a count action for SQL injection does not block the requests; it only logs them. The requirement is to block SQL injection attempts. Additionally, an allow rule for the header does not block requests missing it, so the header requirement is not enforced.

  • ✗

    A web ACL with a rule that blocks requests missing the header, and a rule that uses a regex pattern set to block SQL injection attempts.

    Why it's wrong here

    While a regex pattern set can detect some SQL injection patterns, AWS WAF provides a dedicated SQL injection match condition that is more robust and easier to maintain. Using regex for SQL injection is error-prone and not the recommended approach, though it could work in limited cases.

  • ✗

    A web ACL with a rate-based rule to limit requests and a rule that uses the SQL injection match condition to block malicious requests.

    Why it's wrong here

    A rate-based rule limits request volume but does not enforce the presence of a specific header. The requirement to allow only requests with a specific header is not met by rate limiting. The SQL injection rule is correct, but the header enforcement is missing.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.