WAF Flashcards
WAF means
Web applications firewall
What does WAF do?
Prevents common attack patterns, and attempts to distinguish between genuine and malicious requests.
What do WAF conditions do?
Allow you to specify conditions that WAF should consider.
What are the two types of WAF rules?
Regular
Rate Based
When to use WAF?
Always!
Web ACL rules are executed sequentially. True or false?
True
Web ACL outcomes are?
Allow
Block
Count
WAF charges on three components. They are…
Number of incoming requests
Number of web ACLs
Number of rules in an ACL
WAF Limitations: rate based rules per account
5
WAF Limitations: ACL Limit
50 per account
Generally speaking. WAF rules should be grouped in this order
Whitelist
Blacklist
Bad signature