AWS Certified Advanced Networking – Specialty ANS-C00 – Question251

Your company just deployed a WAF to protect its resources. You need to create a baseline before you start blocking traffic. How will you achieve this?

A.
Set the WAF to Monitor mode.
B. Set the WAF to its defaults and let it do its job.
C. Setup a Lambda function to monitor Flow Logs and analyze the traffic using Elasticsearch.
D. A WAF is default deny and does not allow this. You need to use an IDS instead.

Correct Answer: A

Explanation:

Explanation:
Monitor mode is the only good choice.