Question 1 of 30
A company is deploying a web application that handles sensitive customer data. To enhance security, they decide to implement a Web Application Firewall (WAF) with specific rules to protect against common threats such as SQL injection and cross-site scripting (XSS). The WAF is configured to log all requests that match certain patterns. During a security audit, the team notices that legitimate traffic is being blocked due to overly strict rules. They need to adjust the WAF rules to balance security and usability. Which approach should they take to refine their WAF rules effectively?
Implement a rule set that allows for whitelisting of known safe IP addresses while maintaining strict filtering for all other traffic.
Disable all existing rules and start from scratch to avoid any conflicts with legitimate traffic.
Increase the sensitivity of the existing rules to catch more potential threats, even if it means blocking some legitimate traffic.
Set the WAF to log all traffic without filtering to identify patterns before applying any rules.

Preparing for Amazon SOA-C02 AWS Certified SysOps Administrator – Associate (SOA-C02)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free