AWS WAF filters web traffic using rules, and the exam expects you to know the main rule types you can build to block bad requests.

The rule building blocks

Managed rule groups — AWS/vendor-maintained sets covering common threats (OWASP Top 10, bad bots). Rate-based rules — block an IP that exceeds a request threshold (basic flood/brute-force protection). IP set rules — allow/block specific IPs. String/regex match & geo-match — match request content or country. Flooding from one IP? Rate-based rule.

Test yourself

Practice question

A login page is being brute-forced by a single IP sending thousands of requests per minute. Which WAF rule type stops this most directly?

  1. A geo-match rule
  2. A rate-based rule
  3. A managed SQL-injection rule
  4. An IP allow-list
👉 Click to reveal the answer & explanation

Correct answer: B. A rate-based rule blocks an IP once it exceeds a request threshold — directly countering brute-force/flooding from one source. Geo-match (A) filters by country; a SQL-injection rule (C) targets a different exploit; an allow-list (D) permits IPs rather than throttling abuse.

Related topics

AWS WAF · AWS Shield · AWS Firewall Manager

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access