A web application running on EC2 instances behind an ALB and fronted by CloudFront was attacked. An AWS WAF web ACL is associated with the CloudFront distribution. The company needs to analyze attacks detected by WAF using Amazon Athena. What solution will enable this analysis?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure the AWS WAF web ACL to send logs to an Amazon Kinesis Data Firehose delivery stream, and configure the stream to deliver the data to an S3 bucket for analysis..
Why this is the answer
The correct solution is to configure the AWS WAF web ACL to send logs to an Amazon Kinesis Data Firehose delivery stream, which then delivers the data to an S3 bucket for analysis. AWS WAF logs contain detailed information about requests that WAF inspects, including blocked requests, which is essential for analyzing attacks detected by WAF. Kinesis Data Firehose provides a managed way to stream these logs to S3, where Athena can query them. VPC Flow Logs capture network traffic metadata, not WAF-specific attack details. CloudTrail records API calls and account activity, not web request details processed by WAF. ALB access logs provide information about requests reaching the ALB, but they do not contain the specific WAF action (e.g., blocked by WAF rule) that is crucial for analyzing WAF-detected attacks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed