Notifications
Clear all
Topic starter
18/05/2022 5:32 am
A SOC analyst is reviewing malicious activity on an external, exposed web server. During the investigation, the analyst determines specific traffic is not being logged, and there is no visibility from the WAF for the web application.
Which of the following is the MOST likely cause?
- A . The user agent client is not compatible with the WA
- C . A certificate on the WAF is expired.
- D . HTTP traffic is not forwarding to HTTPS to decrypt.
- E . Old, vulnerable cipher suites are still being used.
Suggested Answer: B
Explanation:
Reference: https://aws.amazon.com/premiumsupport/knowledge-center/waf-block-http-requests-no-user-agent/
Explanation:
Reference: https://aws.amazon.com/premiumsupport/knowledge-center/waf-block-http-requests-no-user-agent/