← AWS Security Specialty: evidence-based security
13 / 14 · 75 MIN

Infrastructure: paths, inspection, and limits

Follow a request from its network path to the application control and identify where protection stops observing.

1. Draw the path before changing the rule

Start with a concrete flow: source, destination, protocol, port, and return direction. With a central firewall, resource existence does not establish that traffic traverses it. Network Firewall needs both directions at the same endpoint; appliance mode on the inspection VPC attachment and consistent routes are part of the Transit Gateway design. Next, observe the transition between engines: stateless Pass ends inspection, while Forward to stateful rules permits continuation through the stateful engine. During diagnosis, changing an application signature without confirming this path can consume the window without addressing the cause. Record one hypothesis per layer and the observation that could disprove it.

2. Scope the source and matching criterion

A domain list can be correct yet exclude the expected source. Default HOME_NET represents the firewall VPC; a central design needs to declare the other covered networks. The list uses SNI for HTTPS and Host for HTTP. This is not an external DNS lookup and does not itself establish that an IP belongs to a partner. In an integration review, separate the presented name, authenticated identity, and authorized path. Ask the team to explain which requirement each control demonstrates. For production handover, include a covered source, another that should be covered, and a destination that must be refused. These authorized rehearsals check the boundary the policy intends to create.

3. Read the order the engine actually applies

Under action order, action takes precedence over priority: pass is evaluated before drop. Do not use visual position or number alone to explain a result. Under strict order, groups follow ascending priority and rules follow the defined sequence within each group. The default action is also part of the policy. If Drop all discards SYN, a rule waiting for SNI never observes ClientHello. The design must permit the phase needed to identify the protocol and block other traffic according to requirements. The local exercise below classifies synthetic forwarding observations. It does not interpret packets, run Suricata, or replace testing of the real policy.

4. Distinguish delivered bytes from inspected bytes

WAF observes only the content the hosting service forwards within applicable limits. On ALB, the body limit is 8 KB; the option to reach 64 KB on other services must not be transferred to this design. Continue evaluates the available portion. Match treats oversize as a match, but rule action still matters: Count does not become Block. If allowed, the complete request can reach the application. For a 24 KB operational upload, acceptance needs to demonstrate the required whole-file validation before processing through a supported design. A successful delivery test proves only delivery. Record size, path, validation mechanism, and expected result before accepting the flow.

5. Confirm effective compute configuration

For IMDS, distinguish default, effective value, and enforcement. Launch value takes precedence over account default, which precedes AMI configuration; IMDSv2 enforcement is evaluated afterwards. A template specifying optional can fail when the account requires tokens. Changing only the default does not modify existing instances. Plan fleet discovery and validate compatibility before changing options. In containers, a hop limit of 1 can prevent the PUT response reaching the consumer even when the host obtains tokens. Investigate that path without automatically weakening the IMDSv2 requirement. Closure criteria should include observed configuration on representative instances and operation of agents depending on metadata.

6. Turn controls into operational acceptance

For Inspector in exclusively agent-based mode, confirm that the instance is SSM-managed and supplies inventory. An installed agent does not prove operation, connectivity, or sufficient permissions. Absence of findings must be read alongside coverage and last scan time. In the weekend scenario, prepare a matrix with source, control, observation, owner, and rollback condition. The technical manager coordinates networking, security, application, and RUN teams so each knows what it needs to demonstrate. Summarize to the sponsor what passed and what remains unproven. This lesson practice is to follow dependencies in order: path, scope, evaluation, observation, and acceptance. That avoids substituting an administrative state for demonstrated operation.

# Original diagnostic model for fictional observations, not a firewall emulator.
# No credentials, network calls, or AWS changes.
def gaps(row):
 missing = []
 if row["outbound_endpoint"]!= row["return_endpoint"]:
 missing.append("asymmetric")
 if row["stateless_action"]!= "forward":
 missing.append("not-forwarded")
 if not row["source_in_scope"]:
 missing.append("source-scope")
 return missing
baseline = dict(outbound_endpoint="a", return_endpoint="a",
 stateless_action="forward", source_in_scope=True)
assert gaps(baseline) == []
assert gaps({**baseline, "return_endpoint": "b"}) == ["asymmetric"]
assert gaps({**baseline, "stateless_action": "pass"}) == ["not-forwarded"]
assert gaps({**baseline, "source_in_scope": False}) == ["source-scope"]
assert gaps({**baseline, "return_endpoint": "b", "source_in_scope": False}) == ["asymmetric", "source-scope"]
print("five path-scope cases passed; no gaps is not proof of security")
IN PRACTICE

One VPC pilot passes, but a second has asymmetric return routing and is missing from HOME_NET; expansion awaits correction and representative rehearsal.

Common pitfalls

Stateless Pass as continuation; name as identity; Count as Block; delivery as inspection; default as a whole-fleet change.

Related topics: Telemetry and investigation scope · Operational handover and acceptance criteria

Take this idea with you

Protection supports a decision only when the path, population, and inspection limits have been demonstrated.

Create account

Reference: Network Firewall rule actions · SCS-C03

AWS is a trademark of Amazon.com, Inc. or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by AWS. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.