A company uses AWS WAF to protect a custom public API running on Amazon EC2 behind an Application Load Balancer. The web ACL uses an AWS Managed Rules rule group. After a software upgrade to the API and its client, some requests fail and cause instability. Logging was not enabled on the web ACL. The security engineer enables AWS WAF logging to Amazon CloudWatch Logs and must immediately restore service, identify the issue, and ensure logging cannot be disabled in the future. Which additional steps should the engineer take?
Choose an answer
Tap an option to check your answer.
Correct answer: Update the web ACL so certain rules use the Count action. Review the logs to identify the blocking rule. Modify the IAM policies for all AWS WAF administrators to prevent removal of logging configurations for any AWS WAF web ACLs..
Why this is the answer
To immediately restore service and identify the issue, changing blocking rules to Count allows requests to pass while still logging which rules would have blocked them. This helps pinpoint the problematic rule without disrupting traffic. Challenge would still block some requests, defeating the immediate restoration goal. Reviewing the logs then identifies the specific rule causing the instability. To prevent future disabling of logging, modifying IAM policies for administrators is the correct approach. AWS WAF does not support resource policies for this purpose; resource policies are typically used for cross-account access or service-specific permissions, not for restricting administrative actions on logging configurations within the same account.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed