AWS WAF is a web application firewall. It filters HTTP/HTTPS requests to your app based on rules — blocking SQL injection, cross-site scripting, bad IPs, and flood traffic before they reach your servers.
WAF vs Shield
WAF protects at layer 7 (the application) against web exploits and lets you write custom rules. Shield protects against DDoS attacks (layers 3/4 and 7). Question about blocking SQL injection or filtering web requests? WAF. Question about large-scale DDoS? Shield. They’re often used together, attached to CloudFront or an ALB.
Test yourself
A web app is being hit with SQL injection attempts in request parameters. What should you deploy to filter these malicious requests?
- AWS Shield Standard
- AWS WAF with a SQL-injection rule
- A security group
- Amazon GuardDuty
👉 Click to reveal the answer & explanation
Correct answer: B. AWS WAF inspects HTTP requests and blocks web exploits like SQL injection using managed or custom rules. Shield (A) handles DDoS, not injection; security groups (C) filter by IP/port, not request content; GuardDuty (D) detects threats but doesn’t block web requests inline.
Related topics
AWS Shield · Amazon CloudFront · Security groups vs NACLs
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first