After a deployment a web application was found vulnerable to cross-site scripting (XSS) during penetration testing, which could expose user data. Which AWS service can help protect the application from this type of attack?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS WAF.
Why this is the answer
AWS WAF (Web Application Firewall) is the correct choice because it helps protect web applications from common web exploits, including XSS, by allowing you to define custom rules to block malicious traffic. It operates at Layer 7 of the OSI model, inspecting HTTP/HTTPS requests for patterns indicative of attacks. AWS Shield Standard provides basic DDoS protection but doesn't offer application-layer attack mitigation like XSS. Elastic Load Balancing distributes incoming application traffic across multiple targets but doesn't inherently provide security against web exploits. Amazon Cognito manages user authentication and authorization but does not protect the application itself from XSS vulnerabilities.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed