WAF: application protection and operations
Six lessons, 30 questions, and six cases on WAF, rules, inspection, false positives, rate limits, and production changes.
Objectives and progression
A technical course with six modules and fictional APS scenarios. Learn to analyze coverage, terminating actions, parsing, oversize handling, exclusions, client origin, quotas, and logs. Distinguish selected AWS WAF behavior and OWASP CRS principles. Includes an internal assessment of 24 decisions in 60 minutes with primary references and explanations for alternatives.
Audience: APS L2/L3, application security, middleware, platform teams, and technical managers.
Prerequisites: HTTP/HTTPS, TLS, and proxy fundamentals; exercises provide necessary conditions.
300 estimated study minutes
- Identify what WAF observes, which paths are protected, and which controls remain necessary.
- Interpret rule evaluation without confusing observation with permission or blocking.
- Assess body coverage, JSON fallback, and transformations.
- Tune rules using evidence while retaining protection outside the exception.
- Choose control keys and actions without assuming one person per IP.
- Correlate decisions and prepare policy changes with regression and recovery.
Modules
- WAF architecture and coverage
- Order, actions, and overrides
- Parsing and inspection limits
- Tuning and false positives
- Rate, origin, and clients
- Logs, changes, and RUN handover
Continue learning
References and version
DR WAF 2026-09; selected AWS WAF and OWASP CRS operational concepts
- OWASP WAF overview · 2026-09-30
- OWASP authorization checks · 2026-09-30
- OWASP virtual patching lifecycle · 2026-09-30
- AWS WAF rule actions · 2026-09-30
- AWS WAF rule priority · 2026-09-30
- AWS WAF individual and group action overrides · 2026-09-30
- AWS WAF inspection and oversize handling · 2026-09-30
- AWS WAF components and JSON fallback · 2026-09-30
- AWS WAF text transformations · 2026-09-30
- OWASP CRS anomaly scoring · 2026-09-30
- OWASP CRS false positives and exclusions · 2026-09-30
- OWASP CRS paranoia levels · 2026-09-30
- AWS WAF rate rule actions · 2026-09-30
- AWS WAF aggregation keys · 2026-09-30
- AWS WAF approximate rate limiting and update caveats · 2026-09-30
- AWS WAF forwarded IP handling · 2026-09-30
- AWS WAF logging and separate sampling protection · 2026-09-30
- AWS WAF log fields · 2026-09-30
- AWS WAF testing and propagation · 2026-09-30
- AWS WAF managed rule versions · 2026-09-30
What you will explore
0 / 6WAF architecture and coverage
Identify what WAF observes, which paths are protected, and which controls remain necessary.
Order, actions, and overrides
Interpret rule evaluation without confusing observation with permission or blocking.
Parsing and inspection limits
Assess body coverage, JSON fallback, and transformations.
Tuning and false positives
Tune rules using evidence while retaining protection outside the exception.
Rate, origin, and clients
Choose control keys and actions without assuming one person per IP.
Logs, changes, and RUN handover
Correlate decisions and prepare policy changes with regression and recovery.