A company hosts its public website on Amazon EC2 instances behind an Application Load Balancer (ALB). The site is under a global DDoS attack from a specific IoT device brand that has a distinctive User-Agent header. A security engineer is creating an AWS WAF web ACL to associate with the ALB and must add a rule that blocks these requests now and in the future without affecting customers. Which rule statement meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Use a string match rule statement that matches the IoT device brand details in the User-Agent header..
Why this is the answer
The correct answer is to use a string match rule statement that matches the IoT device brand details in the User-Agent header. This approach directly targets the distinctive characteristic of the attacking devices, allowing AWS WAF to block only those specific requests without impacting legitimate users. Using an IP set match rule is ineffective because the attacking IoT devices likely have dynamic or distributed IP addresses, making it impossible to block them all with a static IP list. A geographic match rule would block all traffic from entire countries, which would severely impact legitimate customers and is not precise
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed