For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 5Question 27
    Easy1 markMultiple Choice
    Domain 1.2: Security ControlsSecurityWAFALB

    AWS SAP-C02 · Question 27 · Domain 1.2: Security Controls

    A company has a web application deployed on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses Amazon RDS for MySQL. The security team wants to implement a Web Application Firewall (WAF) to protect against SQL injection and cross-site scripting (XSS) attacks. They also want to block requests from specific countries. Where should the Architect deploy AWS WAF?

    Answer options:

    A.

    Attach AWS WAF directly to the Application Load Balancer (ALB).

    B.

    Deploy AWS WAF on the EC2 instances using the AWS Systems Manager agent.

    C.

    Attach AWS WAF to the Amazon RDS database to inspect incoming SQL queries.

    D.

    Create a VPC Network Access Control List (NACL) to block the specific countries and use AWS Shield for SQL injection protection.

    How to approach this question

    Identify the supported integration points for AWS WAF.

    Full Answer

    A.Attach AWS WAF directly to the Application Load Balancer (ALB).✓ Correct
    Attach AWS WAF directly to the Application Load Balancer (ALB).
    AWS WAF is a web application firewall that helps protect web applications from common web exploits. It can be deployed on Amazon CloudFront, Application Load Balancers (ALB), Amazon API Gateway, and AWS AppSync. Attaching it to the ALB allows it to inspect all incoming traffic for SQLi, XSS, and apply geo-blocking rules.

    Common mistakes

    Thinking WAF can be installed on EC2 or attached to RDS.
    Question 26All questionsQuestion 28

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 5

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is redesigning its AWS network architecture across 50 AWS accounts and 3 AWS ...HardQ02A company uses AWS Organizations to manage multiple accounts. The security team mandates that no ...MediumQ03A financial institution requires a disaster recovery strategy for its critical trading applicatio...HardQ04An enterprise is setting up a new multi-account AWS environment using AWS Control Tower. They nee...MediumQ05A company has a complex AWS environment with hundreds of linked accounts under AWS Organizations....Hard
    View all 75 questions →