[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cheat-sheet---en":3,"domain-info---en":3,"topic-info----en":3,"lesson-aws-certified-cloudops-engineer-associate-networking-content-delivery-dns-and-content-delivery-global-accelerator-vs-cloudfront-en":4,"prev-aws-certified-cloudops-engineer-associate-networking-content-delivery-dns-and-content-delivery-global-accelerator-vs-cloudfront-en":19,"next-aws-certified-cloudops-engineer-associate-networking-content-delivery-dns-and-content-delivery-global-accelerator-vs-cloudfront-en":33},null,{"locked":5,"reason":6,"meta":7,"item":3},true,"paywall",{"title":8,"description":9,"isFree":10,"estimatedMinutes":11,"difficulty":12,"learningObjectives":13},"Global Accelerator against CloudFront","Both services put AWS edge locations in front of your workload, and only one of them caches. This lesson covers Global Accelerator's anycast static IPs, listeners, endpoint groups, and traffic dials, then draws the boundary that decides which service a scenario is describing.",false,24,"intermediate",[14,15,16,17,18],"Explain how anycast static IP addresses and the AWS global network shorten the path from a client to a regional endpoint","Describe the components of a standard accelerator: listeners, endpoint groups, endpoints, and network zones","Distinguish a traffic dial from an endpoint weight and choose the right one for a given traffic-shifting requirement","Compare standard accelerators with custom routing accelerators","Choose between CloudFront and Global Accelerator from the protocol, cacheability, and addressing constraints in a scenario",{"locked":5,"reason":6,"meta":20,"item":3},{"title":21,"description":22,"isFree":10,"estimatedMinutes":23,"difficulty":24,"learningObjectives":25},"CloudFront Distributions","A CloudFront distribution is a set of rules that decide, at an edge location, whether to answer from cache or ask your origin. This lesson covers cache behaviors and their matching order, the cache key, the TTL rules that override your Cache-Control headers, invalidation, HTTPS with custom domains, and locking the origin down with OAC.",32,"advanced",[26,27,28,29,30,31,32],"Describe the path a request takes through an edge location, a regional edge cache, and the origin, and name the requests that skip the regional edge cache","Order cache behaviors correctly and predict which one applies to a given request path","Explain what the cache key is and identify the settings that lower a cache hit ratio","Predict the cached duration of an object from the Minimum, Maximum, and Default TTL values and the origin's Cache-Control header","Choose between invalidation and versioned file names for a content update","Configure an alternate domain name with HTTPS, including the Region an ACM certificate must live in","Lock an S3 origin to a distribution with origin access control and explain why OAC replaced OAI",{"locked":10,"reason":3,"meta":34,"item":45},{"title":35,"description":36,"isFree":5,"estimatedMinutes":37,"difficulty":12,"learningObjectives":38},"Auditing Network Protection Services","AWS WAF, Shield, Network Firewall, and Route 53 Resolver DNS Firewall each guard a different piece of traffic, and each has a way of looking deployed while blocking nothing. This lesson gives you a repeatable audit for all 4 in a single account.",28,[39,40,41,42,43,44],"Distinguish AWS WAF, AWS Shield, AWS Network Firewall, and Route 53 Resolver DNS Firewall by the traffic each one actually sees","Apply a 4-question audit frame to any network protection service: deployed, attached, enforcing, observable","Find the AWS WAF configurations that make a web ACL look protective while it blocks nothing","Verify that a Network Firewall is inspecting traffic instead of merely existing, using subnets, endpoints, and route tables","Check a DNS Firewall configuration for rule group association, rule action, priority, and failure mode","Assemble standing audit evidence from CLI calls, service logs, CloudWatch metrics, AWS Config, and Security Hub",{"id":46,"title":35,"body":47,"description":36,"difficulty":12,"estimatedMinutes":37,"extension":976,"infographics":977,"isFree":5,"learningObjectives":991,"meta":992,"navigation":5,"path":993,"quiz":994,"seo":1076,"stem":1077,"__hash__":1078},"courses/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/04-network-protection-and-cost/01-auditing-network-protection-services.md",{"type":48,"value":49,"toc":966},"minimark",[50,59,62,67,70,75,171,174,181,187,191,194,222,225,229,236,350,357,360,377,383,389,395,416,420,423,429,435,442,472,475,478,499,502,506,509,524,530,533,539,545,555,592,595,642,649,656,660,663,669,717,723,758,773,779,799,823,829,851,854,857,861,864,870,876,885,896,900,959,962],[51,52,53,54,58],"p",{},"Compliance sends one line: confirm that every internet-facing application in the production account is protected by a web application firewall. You open the console, find a web ACL named ",[55,56,57],"code",{},"prod-web-acl"," with 14 rules including the AWS managed core rule set, and reply that you are covered.",[51,60,61],{},"You may have just signed off on nothing. A web ACL is a standalone resource. Until it is associated with a specific CloudFront distribution or load balancer, it inspects zero requests, and the console page looks identical either way. The same shape of gap exists in all 4 of the services in this lesson, which is why the exam has a skill statement for auditing them rather than for configuring them.",[63,64,66],"h2",{"id":65},"four-services-four-different-pieces-of-traffic","Four services, four different pieces of traffic",[51,68,69],{},"Before you can audit these services you have to know what each one is even in a position to see. They are not layers of the same wall. They sit on different paths, and a gap in one is completely invisible to the other 3.",[71,72],"infographic",{"alt":73,"slug":74},"A diagram of a VPC showing Shield at the network edge, AWS WAF in front of HTTP application resources, Network Firewall at the VPC perimeter on both the inbound and outbound paths, and DNS Firewall on the branch from the workload to the Route 53 Resolver.","network-protection-services-traffic-paths",[76,77,78,97],"table",{},[79,80,81],"thead",{},[82,83,84,88,91,94],"tr",{},[85,86,87],"th",{},"Service",[85,89,90],{},"Traffic it inspects",[85,92,93],{},"Where it attaches",[85,95,96],{},"Cost model",[98,99,100,115,129,143,157],"tbody",{},[82,101,102,106,109,112],{},[103,104,105],"td",{},"AWS Shield Standard",[103,107,108],{},"Layer 3 and 4 volumetric floods",[103,110,111],{},"Automatic for all AWS customers",[103,113,114],{},"Free",[82,116,117,120,123,126],{},[103,118,119],{},"AWS Shield Advanced",[103,121,122],{},"Layer 3, 4, and 7 DDoS on named resources",[103,124,125],{},"Per-resource protections you create",[103,127,128],{},"$3,000 per month, 1-year commitment",[82,130,131,134,137,140],{},[103,132,133],{},"AWS WAF",[103,135,136],{},"HTTP and HTTPS requests",[103,138,139],{},"Web ACL associated with a supported resource",[103,141,142],{},"Per web ACL, per rule, per million requests",[82,144,145,148,151,154],{},[103,146,147],{},"AWS Network Firewall",[103,149,150],{},"Packets and flows at the VPC perimeter, any protocol",[103,152,153],{},"Firewall endpoints in dedicated subnets, reached by route table entries",[103,155,156],{},"Per endpoint hour and per GB processed",[82,158,159,162,165,168],{},[103,160,161],{},"Route 53 Resolver DNS Firewall",[103,163,164],{},"Outbound DNS queries from the VPC",[103,166,167],{},"Rule groups associated with a VPC",[103,169,170],{},"Per query and per domain list",[51,172,173],{},"Two boundaries in that table earn their own sentence.",[51,175,176,180],{},[177,178,179],"strong",{},"AWS WAF sees requests, Network Firewall sees packets."," WAF only exists in front of resource types that speak HTTP: CloudFront distributions, Application Load Balancers, API Gateway REST APIs, AppSync GraphQL APIs, Cognito user pools, App Runner services, Bedrock AgentCore Gateways, Verified Access instances, and Amplify. Nothing else. If your workload is a database replica shipping data over a custom TCP port, WAF is not the control that could ever have caught it, and Network Firewall is.",[51,182,183,186],{},[177,184,185],{},"DNS Firewall sees queries, Network Firewall sees connections."," Both can filter by domain name, and that overlap is a favorite exam trap. DNS Firewall filters the DNS lookup itself as it passes through the Route 53 VPC Resolver, so it stops the workload from ever learning the address. Network Firewall inspects the resulting traffic on the wire but has no visibility into Resolver queries at all. AWS states this directly: the 2 services filter domain names on 2 different network paths.",[63,188,190],{"id":189},"the-4-questions-an-audit-answers","The 4 questions an audit answers",[51,192,193],{},"Every one of these services can be deployed and still protect nothing, and the failure is always one of the same 4 steps. Carry this frame through the rest of the lesson and apply it to whatever service the exam names:",[195,196,197,204,210,216],"ol",{},[198,199,200,203],"li",{},[177,201,202],{},"Is it deployed?"," Does the resource exist in this account and Region?",[198,205,206,209],{},[177,207,208],{},"Is it attached to what you think?"," Association, subnet, route, or VPC binding.",[198,211,212,215],{},[177,213,214],{},"Is it enforcing, or only observing?"," Count, Alert, and Pass all produce healthy-looking telemetry while permitting the traffic.",[198,217,218,221],{},[177,219,220],{},"Can you prove what it did?"," Logging is off by default on most of these, and an audit without evidence is an opinion.",[51,223,224],{},"Question 3 is where real environments fail, because step 3 is a normal and correct part of every rollout. You start a new rule in count mode on purpose. Nobody schedules the day you turn it on.",[63,226,228],{"id":227},"auditing-aws-waf","Auditing AWS WAF",[51,230,231,232,235],{},"Start with the association, because that is the question the auditor actually asked. Web ACLs live in 2 separate scopes, and the CloudFront scope only exists in ",[55,233,234],{},"us-east-1",":",[237,238,243],"pre",{"className":239,"code":240,"language":241,"meta":242,"style":242},"language-bash shiki shiki-themes material-theme-lighter github-light github-dark","# Regional resources: ALB, API Gateway, AppSync, Cognito, App Runner, Verified Access\naws wafv2 list-web-acls --scope REGIONAL --region eu-west-1\n\naws wafv2 list-resources-for-web-acl \\\n  --web-acl-arn arn:aws:wafv2:eu-west-1:111122223333:regional/webacl/prod-web-acl/a1b2c3d4 \\\n  --region eu-west-1\n\n# CloudFront distributions are always in the us-east-1 CLOUDFRONT scope\naws wafv2 list-web-acls --scope CLOUDFRONT --region us-east-1\n","bash","",[55,244,245,254,281,287,301,312,320,325,331],{"__ignoreMap":242},[246,247,250],"span",{"class":248,"line":249},"line",1,[246,251,253],{"class":252},"sutJx","# Regional resources: ALB, API Gateway, AppSync, Cognito, App Runner, Verified Access\n",[246,255,257,261,265,268,272,275,278],{"class":248,"line":256},2,[246,258,260],{"class":259},"sbgvK","aws",[246,262,264],{"class":263},"s_sjI"," wafv2",[246,266,267],{"class":263}," list-web-acls",[246,269,271],{"class":270},"stzsN"," --scope",[246,273,274],{"class":263}," REGIONAL",[246,276,277],{"class":270}," --region",[246,279,280],{"class":263}," eu-west-1\n",[246,282,284],{"class":248,"line":283},3,[246,285,286],{"emptyLinePlaceholder":5},"\n",[246,288,290,292,294,297],{"class":248,"line":289},4,[246,291,260],{"class":259},[246,293,264],{"class":263},[246,295,296],{"class":263}," list-resources-for-web-acl",[246,298,300],{"class":299},"s_hVV"," \\\n",[246,302,304,307,310],{"class":248,"line":303},5,[246,305,306],{"class":270},"  --web-acl-arn",[246,308,309],{"class":263}," arn:aws:wafv2:eu-west-1:111122223333:regional/webacl/prod-web-acl/a1b2c3d4",[246,311,300],{"class":299},[246,313,315,318],{"class":248,"line":314},6,[246,316,317],{"class":270},"  --region",[246,319,280],{"class":263},[246,321,323],{"class":248,"line":322},7,[246,324,286],{"emptyLinePlaceholder":5},[246,326,328],{"class":248,"line":327},8,[246,329,330],{"class":252},"# CloudFront distributions are always in the us-east-1 CLOUDFRONT scope\n",[246,332,334,336,338,340,342,345,347],{"class":248,"line":333},9,[246,335,260],{"class":259},[246,337,264],{"class":263},[246,339,267],{"class":263},[246,341,271],{"class":270},[246,343,344],{"class":263}," CLOUDFRONT",[246,346,277],{"class":270},[246,348,349],{"class":263}," us-east-1\n",[51,351,352,353,356],{},"An empty ",[55,354,355],{},"ResourceArns"," list is the finding. Work the other direction too: list your ALBs and CloudFront distributions and check which ones have no web ACL at all, because a resource with no association will never appear in any web ACL's resource list.",[51,358,359],{},"Once the association is confirmed, 4 configuration details decide whether the web ACL blocks anything.",[51,361,362,365,366,369,370,373,374,376],{},[177,363,364],{},"The default action."," A web ACL applies its default action to every request that no rule terminated on. ",[55,367,368],{},"Allow"," is normal for a public site protected by explicit block rules. ",[55,371,372],{},"Block"," is normal for a locked-down internal API. Reading the default action tells you which model the web ACL was designed for, and a ",[55,375,372],{}," default with a broad allow rule at the top is a very different security posture from what its name suggests.",[51,378,379,382],{},[177,380,381],{},"Terminating and non-terminating actions."," Allow and Block stop evaluation immediately, and whichever matches first decides the request. Count never terminates: it increments a metric and evaluation continues. CAPTCHA and Challenge are conditional, terminating only when the request has no valid token. So a rule set can be full of well-written block rules that never run.",[51,384,385,388],{},[177,386,387],{},"Rule priority."," AWS WAF evaluates rules from the lowest numeric priority upward. An allow rule at priority 10 that matches your office IP range will terminate before the SQL injection rule at priority 50 ever sees the request. Broad allow rules near the top are the single most productive thing to look for in a web ACL review.",[51,390,391,394],{},[177,392,393],{},"Rule group overrides."," When you add a managed rule group, you can override the whole group's action to Count, or override individual rules inside it. This is the intended way to trial the AWS managed core rule set without breaking a live application. It is also the most common reason a web ACL with excellent rules blocks nothing. Check for it explicitly; the console shows it as a small badge that is easy to skim past.",[51,396,397,398,401,402,405,406,409,410,412,413,415],{},"For question 4, WAF logging is off until you configure it. You can send web ACL logs to a CloudWatch Logs log group, an S3 bucket, or an Amazon Data Firehose delivery stream, and you can redact fields and filter which records are kept. Separately, request sampling gives you a rolling look at recent evaluated requests without any logging setup, which is the fastest way to see whether a rule is matching at all. The CloudWatch metrics to read are ",[55,399,400],{},"AllowedRequests",", ",[55,403,404],{},"BlockedRequests",", and ",[55,407,408],{},"CountedRequests",". A web ACL whose ",[55,411,404],{}," has been flat at zero for months while ",[55,414,408],{}," climbs is telling you the answer to question 3.",[63,417,419],{"id":418},"auditing-aws-shield","Auditing AWS Shield",[51,421,422],{},"Shield splits cleanly into an automatic half and a subscribed half, and the audit questions are different for each.",[51,424,425,428],{},[177,426,427],{},"Shield Standard"," is on for every AWS customer at no extra charge and defends against the common network and transport layer floods. There is nothing to enable, nothing to attach, and nothing to audit beyond knowing it is there.",[51,430,431,434],{},[177,432,433],{},"Shield Advanced"," is a subscription at $3,000 per month with a 1-year commitment, billed per payer account where that payer or any linked account is subscribed. It protects EC2 instances, Elastic Load Balancing load balancers, CloudFront distributions, Route 53 hosted zones, and Global Accelerator standard accelerators.",[51,436,437,438,441],{},"Here is the misconception worth naming: ",[177,439,440],{},"subscribing to Shield Advanced does not protect your resources."," The subscription unlocks the capability. You still create a protection for each resource you want covered. The predictable audit finding is a load balancer created 3 months after the subscription started that nobody added, and the account is paying $3,000 a month partly for coverage it does not have.",[237,443,445],{"className":239,"code":444,"language":241,"meta":242,"style":242},"aws shield describe-subscription          # is the account subscribed, and when does the term end\naws shield list-protections               # which resource ARNs are actually protected\n",[55,446,447,460],{"__ignoreMap":242},[246,448,449,451,454,457],{"class":248,"line":249},[246,450,260],{"class":259},[246,452,453],{"class":263}," shield",[246,455,456],{"class":263}," describe-subscription",[246,458,459],{"class":252},"          # is the account subscribed, and when does the term end\n",[246,461,462,464,466,469],{"class":248,"line":256},[246,463,260],{"class":259},[246,465,453],{"class":263},[246,467,468],{"class":263}," list-protections",[246,470,471],{"class":252},"               # which resource ARNs are actually protected\n",[51,473,474],{},"Diff that protection list against the eligible resources in the account. That diff is your finding.",[51,476,477],{},"Three more Shield Advanced settings carry real audit weight:",[479,480,481,487,493],"ul",{},[198,482,483,486],{},[177,484,485],{},"Automatic application layer DDoS mitigation"," can be configured to count or to block the web requests it identifies as part of an attack. Set to count, it is a detector. Enabling it adds a rule group consuming 150 WCUs to the associated web ACL, which counts against the web ACL's capacity.",[198,488,489,492],{},[177,490,491],{},"Health-based detection"," associates a Route 53 health check with a protected resource so Shield can distinguish a real impact from a benign traffic spike. It is available for every resource type except Route 53 hosted zones, and proactive engagement by the Shield Response Team only works on resources that have it enabled.",[198,494,495,498],{},[177,496,497],{},"Shield Response Team access"," additionally requires a Business or Enterprise Support plan. A subscription without the support plan means the phone number in your runbook does not work.",[51,500,501],{},"Shield Advanced also offers cost protection against bill spikes caused by an attack, granted as service credits after the fact rather than as an automatic discount.",[63,503,505],{"id":504},"auditing-aws-network-firewall","Auditing AWS Network Firewall",[51,507,508],{},"Network Firewall has the largest gap between \"the resource exists\" and \"the resource is doing something\", so this is the deepest of the 4 audits.",[51,510,511,512,515,516,519,520,523],{},"The service creates a ",[177,513,514],{},"firewall endpoint"," in each subnet you designate, and each endpoint gives the firewall availability in its Availability Zone. A ",[177,517,518],{},"firewall policy"," holds the settings and points at ",[177,521,522],{},"rule groups",", stateless and stateful. None of that puts the firewall in the traffic path.",[51,525,526,529],{},[177,527,528],{},"Route tables are the enforcement mechanism."," You edit VPC route tables so a protected subnet's traffic goes to the firewall endpoint, and so return traffic from the internet gateway comes back through the endpoint before reaching the subnet. Skip that step and you have a fully configured firewall with a monthly bill and zero packets. When a scenario says the firewall is deployed and correctly configured but traffic is not being filtered, the routes are the answer.",[51,531,532],{},"Four more checks, in the order they usually bite:",[51,534,535,538],{},[177,536,537],{},"Availability Zone coverage."," One endpoint per AZ, and the endpoint's availability is scoped to its own zone. Workloads in an AZ with no firewall endpoint are unfiltered, or their traffic crosses an AZ boundary to reach an endpoint elsewhere and picks up cross-zone data transfer charges on the way. Compare the list of AZs holding workload subnets against the list of AZs holding firewall subnets.",[51,540,541,544],{},[177,542,543],{},"Dedicated firewall subnets."," A firewall endpoint cannot filter traffic entering or leaving the subnet it lives in. Put a workload in a firewall subnet and that workload is exempt from inspection. AWS is explicit: use firewall subnets for nothing else.",[51,546,547,550,551,554],{},[177,548,549],{},"Stateless default actions."," The stateless engine runs first and decides whether each packet is passed, dropped, or forwarded to the stateful engine. If the stateless default action is ",[55,552,553],{},"Pass"," and no stateless rule forwards traffic onward, your Suricata rules and domain lists never execute. The policy is perfectly valid, which is what makes it an audit finding instead of an error. The same setting has a separate default for UDP packet fragments; Network Firewall silently drops fragments of other protocols.",[51,556,557,560,561,564,565,568,569,401,572,575,576,579,580,583,584,587,588,591],{},[177,558,559],{},"Stateful rule evaluation order."," A policy uses either action order or strict order, and ",[55,562,563],{},"RuleOrder"," can only be set when the policy is created. It cannot be edited afterward. Under action order, Suricata evaluates every ",[55,566,567],{},"pass"," rule before any ",[55,570,571],{},"drop",[55,573,574],{},"reject",", or ",[55,577,578],{},"alert"," rule regardless of the ",[55,581,582],{},"priority"," keyword, so a permissive pass rule anywhere in any rule group overrides everything below it. Under strict order, rule groups run by ascending priority and rules run in the order written, and you also choose default actions such as ",[177,585,586],{},"Drop all"," or ",[177,589,590],{},"Drop established",". AWS recommends strict order for exactly this predictability. If an audit finds a drop rule that never fires, action order plus a broad pass rule is the first hypothesis.",[51,593,594],{},"For evidence, Network Firewall logging is off until you configure it, and it produces 3 log types you enable separately:",[76,596,597,607],{},[79,598,599],{},[82,600,601,604],{},[85,602,603],{},"Log type",[85,605,606],{},"Contents",[98,608,609,617,634],{},[82,610,611,614],{},[103,612,613],{},"Flow",[103,615,616],{},"Standard network traffic flow records for traffic through the stateful engine",[82,618,619,622],{},[103,620,621],{},"Alert",[103,623,624,625,401,628,575,631],{},"Traffic matching stateful rules whose action is ",[55,626,627],{},"DROP",[55,629,630],{},"ALERT",[55,632,633],{},"REJECT",[82,635,636,639],{},[103,637,638],{},"TLS",[103,640,641],{},"TLS inspection events, only when TLS inspection is configured",[51,643,644,645,648],{},"The constraint that catches people: ",[177,646,647],{},"only traffic forwarded to the stateful engine is logged at all."," Stateless drops never appear in these logs. CloudWatch metrics cover both engines and are the right place to confirm the firewall is receiving traffic in the first place.",[51,650,651,652,655],{},"One last item worth recording: ",[177,653,654],{},"delete protection"," is enabled when a firewall is created and must be explicitly turned off through the API before the firewall can be deleted. The console does not show the setting because the deletion flow disables it for you.",[63,657,659],{"id":658},"auditing-route-53-resolver-dns-firewall","Auditing Route 53 Resolver DNS Firewall",[51,661,662],{},"DNS Firewall filters outbound DNS queries as they pass through the Route 53 VPC Resolver. Its headline job is stopping DNS exfiltration, where an attacker who has compromised an instance encodes data into lookups against a domain they control. It also blocks resolution of private hosted zone records, VPC endpoint names, and EC2 instance names.",[51,664,665,668],{},[177,666,667],{},"Association."," Rule groups do nothing until associated with a VPC, and you can associate up to 5 rule groups per VPC per Region. Confirm the association and its priority, then check that the priority order matches your intent, since lower numbers evaluate first both across associated rule groups and among rules inside one group.",[237,670,672],{"className":239,"code":671,"language":241,"meta":242,"style":242},"aws route53resolver list-firewall-rule-group-associations --vpc-id vpc-0abc123\naws route53resolver list-firewall-rules --firewall-rule-group-id rslvr-frg-0abc123\naws route53resolver list-firewall-configs        # the fail-open setting per VPC\n",[55,673,674,690,705],{"__ignoreMap":242},[246,675,676,678,681,684,687],{"class":248,"line":249},[246,677,260],{"class":259},[246,679,680],{"class":263}," route53resolver",[246,682,683],{"class":263}," list-firewall-rule-group-associations",[246,685,686],{"class":270}," --vpc-id",[246,688,689],{"class":263}," vpc-0abc123\n",[246,691,692,694,696,699,702],{"class":248,"line":256},[246,693,260],{"class":259},[246,695,680],{"class":263},[246,697,698],{"class":263}," list-firewall-rules",[246,700,701],{"class":270}," --firewall-rule-group-id",[246,703,704],{"class":263}," rslvr-frg-0abc123\n",[246,706,707,709,711,714],{"class":248,"line":283},[246,708,260],{"class":259},[246,710,680],{"class":263},[246,712,713],{"class":263}," list-firewall-configs",[246,715,716],{"class":252},"        # the fail-open setting per VPC\n",[51,718,719,722],{},[177,720,721],{},"Rule action."," Every rule carries exactly one of 3 actions:",[76,724,725,735],{},[79,726,727],{},[82,728,729,732],{},[85,730,731],{},"Action",[85,733,734],{},"Effect",[98,736,737,744,751],{},[82,738,739,741],{},[103,740,368],{},[103,742,743],{},"Stop inspecting and permit the query",[82,745,746,748],{},[103,747,621],{},[103,749,750],{},"Stop inspecting, permit the query, and log it in the Resolver query logs",[82,752,753,755],{},[103,754,372],{},[103,756,757],{},"Stop inspecting, block the query, log it, and return the configured block response",[51,759,760,761,763,764,766,767,769,770,772],{},"AWS itself recommends creating a blocking rule as ",[55,762,621],{}," first so you can measure how many queries it would have blocked. That advice creates the most common DNS Firewall finding in existence: a rule group where every rule is still on ",[55,765,621],{}," a year later. ",[55,768,621],{}," is a detector; ",[55,771,372],{}," is a control. Reading the action list is a 30 second check with real consequences.",[51,774,775,778],{},[177,776,777],{},"Block response."," When the action is Block, you choose what the client hears back:",[479,780,781,787,793],{},[198,782,783,786],{},[177,784,785],{},"NODATA"," answers that the query succeeded but no record is available.",[198,788,789,792],{},[177,790,791],{},"NXDOMAIN"," answers that the domain name does not exist.",[198,794,795,798],{},[177,796,797],{},"OVERRIDE"," returns a custom CNAME you specify, with a time to live that defaults to 0 so the answer is not cached. This is how you route blocked lookups to a sinkhole or an internal warning page.",[51,800,801,804,805,401,808,401,811,814,815,818,819,822],{},[177,802,803],{},"Managed domain lists."," AWS maintains 4 lists you can use for free: ",[177,806,807],{},"Malware",[177,809,810],{},"Botnet/Command and Control",[177,812,813],{},"Aggregate Threat List"," (a superset of the others, adding ransomware, spyware, and DNS tunneling), and ",[177,816,817],{},"Amazon GuardDuty Threat List"," (domains from GuardDuty's own DNS findings). You cannot view or download their contents, which is deliberate: a published block list is a specification for evading it. When a managed list produces a false positive, the fix is to add an allow rule for that specific domain and give it a ",[177,820,821],{},"lower numeric priority"," than the blocking rule so it runs first.",[51,824,825,828],{},[177,826,827],{},"Failure mode."," This is the setting nobody checks. When VPC Resolver gets no reply from DNS Firewall, the VPC's firewall configuration decides what happens:",[479,830,831,841],{},[198,832,833,836,837,840],{},[177,834,835],{},"Fail closed"," is the default. The query is blocked and VPC Resolver returns ",[55,838,839],{},"SERVFAIL",". Security over availability.",[198,842,843,846,847,850],{},[177,844,845],{},"Fail open",", set through the ",[55,848,849],{},"FirewallFailOpen"," field, lets the query through. Availability over security.",[51,852,853],{},"Both are legitimate choices, and neither is an error. But a fail-open VPC loses its DNS protections during exactly the moments an attacker would want them gone, so the audit finding is not \"fail open is wrong\", it is \"fail open is set and nobody documented the decision\".",[51,855,856],{},"Worth memorizing alongside the config: 5 rule groups per VPC, 100 rules per rule group, 1,000 rule groups per account per Region, 100,000 domains across all your domain lists.",[63,858,860],{"id":859},"turning-spot-checks-into-standing-evidence","Turning spot checks into standing evidence",[51,862,863],{},"Everything above is a point-in-time answer. An audit that has to be repeated by hand every quarter will not be repeated.",[51,865,866,869],{},[177,867,868],{},"AWS Config"," records configuration changes to these resources and evaluates managed rules against them continuously, so a web ACL that loses its association or a firewall policy whose default action changes generates a noncompliant finding on its own. Conformance packs bundle the relevant rules into one deployable unit.",[51,871,872,875],{},[177,873,874],{},"AWS Security Hub"," aggregates those Config findings alongside GuardDuty and Inspector results and scores them against standards such as the AWS Foundational Security Best Practices, which turns \"are we protected\" into a number with a trend line.",[51,877,878,881,882,884],{},[177,879,880],{},"CloudWatch alarms"," close question 3 permanently. An alarm on a web ACL's ",[55,883,404],{}," staying at zero across a full week, or on Network Firewall's packet counters dropping to nothing, catches the silent regressions that a quarterly review misses by 89 days.",[51,886,887,888,891,892,895],{},"One scope note that matters for the exam. This skill is written as auditing these services ",[177,889,890],{},"in a single account",". The moment the question widens to every VPC in every member account, including accounts that do not exist yet, the answer changes to ",[177,893,894],{},"AWS Firewall Manager",", which centrally applies AWS WAF, Shield Advanced, security group, network ACL, Network Firewall, and DNS Firewall policies across an organization and automatically brings new resources into scope. Firewall Manager requires AWS Organizations and AWS Config. Keep it filed as the organization-wide answer so it does not tempt you on a single-account question.",[63,897,899],{"id":898},"exam-tips","Exam tips",[479,901,902,908,914,920,926,931,937,945,954],{},[198,903,904,907],{},[177,905,906],{},"Existence is not protection."," For WAF read the association, for Shield read the protection list, for Network Firewall read the route tables, for DNS Firewall read the VPC association. That single move answers most audit questions on this skill.",[198,909,910,913],{},[177,911,912],{},"Count, Alert, and Pass are the observe-only settings."," WAF Count and rule group overrides, Shield automatic mitigation set to count, Network Firewall stateless default Pass, DNS Firewall Alert. A scenario describing \"logs show the traffic but it is not blocked\" is pointing at one of these.",[198,915,916,919],{},[177,917,918],{},"Domain filtering appears twice."," Queries through the Resolver are DNS Firewall; traffic on the wire is Network Firewall. Network Firewall has no visibility into Resolver queries.",[198,921,922,925],{},[177,923,924],{},"AWS WAF only attaches to HTTP resource types."," CloudFront, ALB, API Gateway, AppSync, Cognito user pools, App Runner, Bedrock AgentCore Gateway, Verified Access, Amplify. Not EC2, not NLB, not RDS.",[198,927,928],{},[177,929,930],{},"Shield Standard is free and automatic; Shield Advanced is $3,000 a month on a 1-year commitment and protects only the resources you explicitly add.",[198,932,933,936],{},[177,934,935],{},"Network Firewall route tables, dedicated firewall subnets, and one endpoint per AZ."," A firewall endpoint cannot filter its own subnet.",[198,938,939,944],{},[177,940,941,943],{},[55,942,563],{}," is set at policy creation and cannot be changed."," Strict order is the recommended choice.",[198,946,947,950,951,953],{},[177,948,949],{},"DNS Firewall fails closed by default"," and returns ",[55,952,839],{},". Fail open is opt-in.",[198,955,956],{},[177,957,958],{},"Single account is the audit; AWS Organizations is Firewall Manager.",[51,960,961],{},"The habit to carry out of this lesson is smaller than the service list: for any protection control, find the binding that connects it to real traffic, then find the setting that decides whether it acts or only watches. Those 2 facts are the audit. The next lesson looks at the same network from the opposite direction, asking not whether it is protected but what every gigabyte crossing it costs you.",[963,964,965],"style",{},"html pre.shiki code .sutJx, html code.shiki .sutJx{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#6A737D;--shiki-default-font-style:inherit;--shiki-dark:#6A737D;--shiki-dark-font-style:inherit}html pre.shiki code .sbgvK, html code.shiki .sbgvK{--shiki-light:#E2931D;--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .s_sjI, html code.shiki .s_sjI{--shiki-light:#91B859;--shiki-default:#032F62;--shiki-dark:#9ECBFF}html pre.shiki code .stzsN, html code.shiki .stzsN{--shiki-light:#91B859;--shiki-default:#005CC5;--shiki-dark:#79B8FF}html pre.shiki code .s_hVV, html code.shiki .s_hVV{--shiki-light:#90A4AE;--shiki-default:#005CC5;--shiki-dark:#79B8FF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":242,"searchDepth":283,"depth":283,"links":967},[968,969,970,971,972,973,974,975],{"id":65,"depth":256,"text":66},{"id":189,"depth":256,"text":190},{"id":227,"depth":256,"text":228},{"id":418,"depth":256,"text":419},{"id":504,"depth":256,"text":505},{"id":658,"depth":256,"text":659},{"id":859,"depth":256,"text":860},{"id":898,"depth":256,"text":899},"md",[978],{"slug":74,"concept":979,"style":980,"aspectRatio":981,"labels":982},"A single VPC drawn as a wide horizontal band in the center, with an inbound traffic path entering from the left (internet to application) and an outbound path leaving to the right (workload to internet). Each of the 4 protection services is placed as a labeled checkpoint at the exact point on a path where it inspects traffic, not floating beside it: Shield furthest left at the network edge, AWS WAF at the HTTP entry point in front of the application resources, Network Firewall straddling the VPC perimeter on both paths, and DNS Firewall on a short branch from the workload up to the Route 53 Resolver. The visual anchor is that no 2 checkpoints sit on the same segment of the same path. A footer strip carries the audit consequence.","diagram","16:9",[983,984,985,986,987,988,989,990],"Inbound path: internet to application","Outbound path: workload to internet","AWS Shield: absorbs layer 3 and 4 volumetric floods before they reach the resource","AWS WAF: inspects HTTP and HTTPS requests at CloudFront, ALB, API Gateway, AppSync, Cognito, App Runner, Verified Access","AWS Network Firewall: inspects packets and flows at the VPC perimeter, any protocol, steered by route tables","Route 53 Resolver DNS Firewall: filters outbound DNS queries that leave the VPC through the Resolver","Route 53 Resolver sits at the VPC network range base plus two","No 2 of these services inspect the same traffic, so a gap in one is invisible to the other three",[39,40,41,42,43,44],{},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/04-network-protection-and-cost/01-auditing-network-protection-services",{"passingScore":995,"questions":996},70,[997,1006,1014,1022,1033,1041,1049,1055,1063,1068],{"question":998,"type":999,"options":1000,"correctAnswer":1002,"explanation":1005},"An auditor asks whether your internet-facing application is protected by AWS WAF. You confirm a web ACL named prod-web-acl exists with 14 rules. What have you actually proven?","single",[1001,1002,1003,1004],"That the application is protected, since the web ACL exists in the same Region","Nothing about the application, because a web ACL only inspects traffic for the resources it is associated with","That the application is protected as long as the default action is Block","That the application is protected unless Shield Advanced is also subscribed","A web ACL is an independent resource that does nothing until it is associated with a CloudFront distribution, ALB, API Gateway REST API, AppSync API, Cognito user pool, App Runner service, Verified Access instance, or Amplify app. Run list-resources-for-web-acl to see the association list, which is the only thing that answers the auditor's question. The default action and Shield subscription matter only after the association exists.",{"question":1007,"type":999,"options":1008,"correctAnswer":1011,"explanation":1013},"A managed rule group in a web ACL is added with the rule group action override set to Count. What is the effect?",[1009,1010,1011,1012],"Requests matching the group are blocked and also counted","The group is evaluated twice, once for metrics and once for enforcement","Every rule in the group is evaluated and counted, but none of them block, so evaluation continues to the next rule","The group is skipped entirely and produces no metrics","Overriding a rule group to Count converts its rule actions to a non-terminating count, which is the correct way to test a new managed rule group but a serious finding if it survives into production. The group still produces CountedRequests metrics and log entries, which is exactly why it looks healthy on a dashboard while blocking nothing. Skipping the group entirely would produce no metrics at all, which is a different and more visible failure.",{"question":1015,"type":999,"options":1016,"correctAnswer":1018,"explanation":1021},"In a web ACL, a rule with the Allow action has priority 10 and a rule that blocks SQL injection patterns has priority 50. A request matches both. What happens?",[1017,1018,1019,1020],"The request is blocked, because Block always wins over Allow","The request is allowed, because rules are evaluated from the lowest numeric priority and Allow is a terminating action","The request is counted by both rules and then the default action applies","AWS WAF rejects the configuration as ambiguous","AWS WAF evaluates rules in ascending numeric priority order, and Allow and Block are both terminating, so the first one that matches decides the request and no later rule is evaluated. A broad Allow rule placed at a low priority silently shadows every protection below it, which is one of the highest-value findings in a web ACL audit. Count is the only plain action that never terminates evaluation.",{"question":1023,"type":1024,"options":1025,"correctAnswers":1031,"explanation":1032},"Which statements about AWS Shield are correct? (Choose 2.)","multiple",[1026,1027,1028,1029,1030],"Shield Standard is included at no additional cost for all AWS customers","Subscribing to Shield Advanced automatically protects every eligible resource in the account","Shield Advanced requires a 1-year subscription commitment and is billed per payer account","Shield Standard provides access to the Shield Response Team","Shield Advanced replaces the need for AWS WAF on protected resources",[1026,1028],"Shield Standard is automatic and free and covers common network and transport layer events, while Shield Advanced is a paid subscription with a 1-year commitment billed at the payer account level. Subscribing does not protect anything on its own: you still add each resource as a protection, which is why a new load balancer created after the subscription is a classic audit gap. Shield Advanced uses AWS WAF for its application layer protections rather than replacing it, and the Shield Response Team is an Advanced feature that also requires Business or Enterprise Support.",{"question":1034,"type":999,"options":1035,"correctAnswer":1039,"explanation":1040},"A Network Firewall exists, its policy has well-written stateful rules, and CloudWatch shows almost no traffic through the firewall. Workload traffic still reaches the internet normally. What do you check first?",[1036,1037,1038,1039],"Whether the stateful rule groups use strict order","Whether the firewall policy has a customer managed KMS key","Whether delete protection is enabled on the firewall","The route tables for the protected subnets, because traffic only reaches the firewall if routes send it to the firewall endpoint","Network Firewall is not inline by default. You steer traffic to it by editing VPC route tables so that the protected subnet sends traffic to the firewall endpoint and the internet gateway sends return traffic back through it. If those routes still point straight at a NAT gateway or internet gateway, the firewall bills every hour and inspects nothing. Rule order, encryption keys, and delete protection all change behavior only for traffic that already arrives.",{"question":1042,"type":999,"options":1043,"correctAnswer":1044,"explanation":1048},"A firewall policy has stateless default actions set to Pass for full packets, and no stateless rule group forwards anything to the stateful engine. What is the result?",[1044,1045,1046,1047],"The stateful rules are never evaluated, so Suricata rules and domain lists have no effect","The stateful rules run anyway, because Pass means continue inspecting","Traffic is dropped because no rule matched","The policy fails validation at creation time","The stateless engine decides whether a packet is passed, dropped, or forwarded to the stateful engine, and only forwarded traffic reaches your Suricata rules and domain lists. A stateless default of Pass sends traffic straight through, which is also why no alert or flow logs appear: firewall logging only covers traffic forwarded to the stateful engine. The policy is valid, which is what makes this a configuration audit finding rather than a deployment error.",{"question":1050,"type":999,"options":1051,"correctAnswer":1053,"explanation":1054},"True or False: if a DNS Firewall rule group is associated with a VPC and Route 53 VPC Resolver receives no reply from DNS Firewall, queries are allowed through by default.",[1052,1053],"True","False","The default DNS Firewall failure mode is closed: VPC Resolver blocks the query and returns SERVFAIL, favoring security over availability. Fail open is an explicit opt-in that you set with the FirewallFailOpen setting on the VPC firewall configuration, and it trades security for availability. Auditing this setting matters because a fail-open VPC quietly loses its DNS protections during an impairment.",{"question":1056,"type":999,"options":1057,"correctAnswer":1059,"explanation":1062},"Six months after rollout, a DNS Firewall rule group still uses the Alert action on the AWS managed Aggregate Threat List. What is the operational consequence?",[1058,1059,1060,1061],"Queries to listed domains are blocked, and the alert only adds a log entry","Queries to listed domains are permitted and logged, so the rule detects exfiltration without stopping it","The managed list is not evaluated until the action is changed to Block","The rule group is ignored because Alert is not valid on a managed domain list","Alert stops inspection, permits the query, and writes a record to the Resolver query logs, which is exactly what AWS recommends while you measure a new rule's blast radius. Leaving it there permanently turns a control into a report. Block is the action that discontinues the query and returns your chosen response, and a stale Alert action is one of the most common findings in a DNS Firewall audit.",{"question":1064,"type":999,"options":1065,"correctAnswer":791,"explanation":1067},"You need a DNS Firewall block response that makes clients believe the domain does not exist. Which block response do you configure?",[791,785,1066,839],"OVERRIDE with a CNAME to a sinkhole","NXDOMAIN answers that the queried domain name does not exist, while NODATA answers that the query succeeded but no record is available, and OVERRIDE returns a custom CNAME with a time to live that defaults to 0 so the answer is not cached. SERVFAIL is not a block response you configure: it is what VPC Resolver returns when a fail-closed VPC gets no reply from DNS Firewall. Choosing between NXDOMAIN and OVERRIDE usually depends on whether you want the client to fail fast or land on a sinkhole page you control.",{"question":1069,"type":999,"options":1070,"correctAnswer":1072,"explanation":1075},"Your organization wants the same DNS Firewall rule groups and Network Firewall policies applied automatically to every VPC in every member account, including accounts created next quarter. What does that require?",[1071,1072,1073,1074],"A CloudFormation StackSet targeting each Region","AWS Firewall Manager, which requires AWS Organizations and AWS Config","Shield Advanced protection groups","A Route 53 Profile shared with AWS RAM","Firewall Manager centrally configures AWS WAF, Shield Advanced, security groups, network ACLs, Network Firewall, and DNS Firewall across an organization, and it automatically brings new accounts and resources into scope. It sits outside a single-account audit, which is where the exam scopes this skill, so treat it as the answer to the organization-wide version of the question. StackSets deploy templates but do not continuously enforce protection scope, and protection groups only cluster resources already protected by Shield Advanced.",{"title":35,"description":36},"courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/04-network-protection-and-cost/01-auditing-network-protection-services","H1DNyH2hRXJaSSVVG36mKsqWAynwf1eCtPpcoiVoo0Q"]