Concept and mechanism
In AWS WAF, rules are evaluated in ascending numeric priority. A terminating action ends that evaluation: Allow before a group can prevent later rules from inspecting the request. Count records a match and lets evaluation continue; it means neither that the request is authorized nor that it was blocked. A Count rule can therefore match while a later Block rule determines the final decision. When reviewing a policy, follow the order using a concrete request and identify the first terminating point. The number of configured rules does not prove that every rule is reached for each path.
Guided application
Also distinguish changing individual actions from overriding only a group result to Count. The latter does not change internal evaluation; a terminating rule can prevent observing other rules in the group. For tuning, establish the scope of each override. CAPTCHA and Challenge have token-dependent behavior and require attention to the client. Do not assume a browserless batch can complete an interactive flow. In an incorrectly blocked export case, a broad Allow restores service but removes later inspection. Review the specific match, residual risk, and necessary regression before accepting the exception as a durable solution.
Priority 10 Allow terminates before priority 20 Block when both would match.
Common pitfalls
Count as Allow; higher priority number as first; group override as every action; batch as browser.
Related topics: WAF architecture and coverage · Parsing and inspection limits · Tuning and false positives
Follow evaluation flow and identify the action that actually decides.
Reference: AWS WAF rule priority · DR WAF 2026-09; selected AWS WAF and OWASP CRS operational concepts