Which AWS service can inspect and block malicious HTTP and HTTPS requests that are sent to Amazon CloudFront distributions?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS WAF.
Why this is the answer
AWS WAF (Web Application Firewall) is the correct service because it helps protect web applications or APIs from common web exploits that could affect availability, compromise security, or consume excessive resources. It allows you to create custom rules to filter and block malicious HTTP and HTTPS requests before they reach your Amazon CloudFront distributions, Application Load Balancers, Amazon API Gateway, or AWS AppSync APIs. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads. Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. Amazon Detective is a service that automatically collects log data from your AWS resources and uses machine learning, statistical analysis, and graph theory to build a linked set of data that enables easier and faster security investigations. While these services are security-related, they do not directly inspect and block malicious HTTP/HTTPS requests at the web application layer like AWS WAF does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed