← Back to catalogue
Professional assessment

WAF: application protection and operations

Six lessons, 30 questions, and six cases on WAF, rules, inspection, false positives, rate limits, and production changes.

BigSavantAvailable
BigSavantWAF6 lessons
Internal assessment of 24 decisions in 60 minutes. Coverage, rules, parsing, tuning, rates, and operations. No external exam or certification.

Objectives and progression

A technical course with six modules and fictional APS scenarios. Learn to analyze coverage, terminating actions, parsing, oversize handling, exclusions, client origin, quotas, and logs. Distinguish selected AWS WAF behavior and OWASP CRS principles. Includes an internal assessment of 24 decisions in 60 minutes with primary references and explanations for alternatives.

Audience: APS L2/L3, application security, middleware, platform teams, and technical managers.

Prerequisites: HTTP/HTTPS, TLS, and proxy fundamentals; exercises provide necessary conditions.

300 estimated study minutes

  • Identify what WAF observes, which paths are protected, and which controls remain necessary.
  • Interpret rule evaluation without confusing observation with permission or blocking.
  • Assess body coverage, JSON fallback, and transformations.
  • Tune rules using evidence while retaining protection outside the exception.
  • Choose control keys and actions without assuming one person per IP.
  • Correlate decisions and prepare policy changes with regression and recovery.

Modules

  1. WAF architecture and coverage
  2. Order, actions, and overrides
  3. Parsing and inspection limits
  4. Tuning and false positives
  5. Rate, origin, and clients
  6. Logs, changes, and RUN handover

Continue learning

Technical assessments

References and version

DR WAF 2026-09; selected AWS WAF and OWASP CRS operational concepts

What you will explore

0 / 6

Learning is also trying.

Original explained questions, flashcards, and scenarios to apply the concepts.

Practice
This module covers foundations. It is not a complete certification course or a full simulation of the official exam.

Assessment topics

Architecture and protection boundaries—
Rule evaluation and actions—
Parsing and inspection limits—
Tuning and false positives—
Rate control and origin—
Diagnosis and changes—