SOA-C02 AWS WAF Inspection Capabilities Practice Question
A company wants to use AWS WAF to protect a web application behind an Application Load Balancer. Which of the following can AWS WAF inspect? (Choose all that apply.)
⚠ Common exam trap
Candidates may mistakenly think that the request body of HTTPS requests cannot be inspected, but AWS WAF can inspect it when used with an Application Load Balancer because the ALB decrypts the traffic before forwarding to WAF.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HTTP headers
AWS WAF inspects the HTTP request components that reach the Application Load Balancer, and HTTP headers (Option A) are one of the core inspectable request parts used in rules such as header-match statements. Query string parameters (Option B) are also inspectable, allowing rules to match on keys/values in the URL query, which is essential for blocking injection or abuse patterns. The request body of HTTPS requests (Option D) can be inspected because AWS WAF supports body inspection (with size limits and sampling behavior) even though the traffic is TLS-encrypted at the ALB, since WAF evaluates the decrypted HTTP request. The URI path (Option E) is inspectable via URI-path match conditions, enabling rules that target specific endpoints or path patterns. Option C is not correct because AWS WAF does not inspect the client's SSL/TLS certificate; client certificate handling/validation is a function of the load balancer's mutual TLS configuration, not a WAF match condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
HTTP headers
Why this is correct
HTTP headers are one of the key web request components that AWS WAF natively inspects. You can create rules that match on header names and values, such as checking the User-Agent header for known bot signatures or the Authorization header for invalid tokens. WAF supports string matching, regex pattern sets, and size constraints on header values, providing flexible control over header-based threats.
- ✓
Query string parameters
Why this is correct
Query string parameters, the key-value pairs in the URL after the '?' character, are directly visible to AWS WAF. Rules can perform exact matches, regex pattern matching, or size checks on the entire query string or on individual parameter names and values. This capability is commonly used to block SQL injection or XSS payloads embedded in request query strings.
- ✗
SSL certificate of the client
Why it's wrong here
The client's SSL certificate is exchanged during the TLS handshake, which terminates at the load balancer or CloudFront edge before AWS WAF processes the request. WAF only evaluates the decrypted HTTP application data forwarded from that front-end, so it never sees certificate fields. Consequently, client certificate attributes cannot be used as match conditions in a WAF rule.
- ✓
Request body of HTTPS requests
Why this is correct
The request body of HTTPS requests is not inspectable by AWS WAF by default; it requires enabling body inspection, which is not a standard capability and has size constraints. Therefore, this is not one of the three common inspects.
- ✓
URI path
Why this is correct
The URI path, which identifies the specific resource in a URL (for example, /api/login), is inspectable by AWS WAF using string or regex-based rules. You can block access to sensitive endpoints, apply rate limits to specific routes, or implement a positive security model that allows only predefined paths. The path is matched exactly as sent in the HTTP request line.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.