AWS WAF is a web application firewall. It filters HTTP/HTTPS requests to your app based on rules — blocking SQL injection, cross-site scripting, bad IPs, and flood traffic before they reach your servers.

WAF vs Shield

WAF protects at layer 7 (the application) against web exploits and lets you write custom rules. Shield protects against DDoS attacks (layers 3/4 and 7). Question about blocking SQL injection or filtering web requests? WAF. Question about large-scale DDoS? Shield. They’re often used together, attached to CloudFront or an ALB.

Test yourself

Practice question

A web app is being hit with SQL injection attempts in request parameters. What should you deploy to filter these malicious requests?

  1. AWS Shield Standard
  2. AWS WAF with a SQL-injection rule
  3. A security group
  4. Amazon GuardDuty
👉 Click to reveal the answer & explanation

Correct answer: B. AWS WAF inspects HTTP requests and blocks web exploits like SQL injection using managed or custom rules. Shield (A) handles DDoS, not injection; security groups (C) filter by IP/port, not request content; GuardDuty (D) detects threats but doesn’t block web requests inline.

Related topics

AWS Shield · Amazon CloudFront · Security groups vs NACLs

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access