Mitigate credential stuffing with the WAF ATP rule and a password-reset redirect for affected users

Answer Correct answer: B, E — the WAF ATP rule blocks compromised-credential logins and a password-reset redirect spares legitimate users from being blocked.

A company has a new web-based account management system for an online game. Players create a unique username and password to log in to the system. The company has implemented an AWS WAF web ACL for the system. The web ACL includes the core rule set (CRS) AWS managed rule group on the Application Load Balancer that serves the system. The company’s security team finds that the system was the target of a credential stuffing attack. Credentials that were exposed in other breaches were used to try to log in to the system. The security team must implement a solution to reduce the chance of a successful credential stuffing attack in the future. The solution also must minimize impact on legitimate users of the system. Which combination of actions will meet these requirements? (Choose two.)

  1. Create an Amazon CloudWatch custom metric to analyze the number of successful login responses from a single IP address.
  2. Add the account takeover prevention (ATP) AWS managed rule group to the web ACL. Configure the rule group to inspect login requests to the system. Block any requests that have the awswaf:managed:aws:atp:signal:credential_compromised label. Correct Answer
  3. Configure a default web ACL action that requires all users to solve a CAPTCHA puzzle when they log in.
  4. Implement IP-based match rules in the web ACL for any IP addresses that generate many successful login responses. Block any IP addresses that generate many successful logins.
  5. Create a custom block response that redirects users to a secure workflow to reset their password inside the system. Correct Answer

Community Votes

AB
63%
BE
37%

63% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The ATP managed rule group is purpose-built to detect credential stuffing/account takeover using AWS's regularly updated compromised-credential corpus and the credential_compromised label. A password-reset redirect on that label addresses the 'minimize impact on legitimate users' requirement: real users with breached credentials are routed to reset rather than locked out, unlike a hard IP block that harms shared-IP legitimate users.

A WAF with the CRS already fronts the login ALB; the company needs to cut credential-stuffing success and avoid penalizing legitimate users. Adding the AWS WAF account takeover prevention (ATP) managed rule group inspects login requests and emits a credential_compromised label for credentials found in AWS's stolen-credential database, which can be blocked. Pairing it with a custom block response that redirects affected users into a secure password-reset workflow stops attackers while letting legitimate users (whose credentials were in breaches) recover instead of being permanently blocked.

Choosing only a CloudWatch custom metric (option A) for successful-logins-per-IP analysis—that is detection/monitoring, not a WAF prevention action, and does not by itself reduce attacks or protect legitimate users. Or a blanket CAPTCHA default action (option C), which degrades all legitimate users' experience, violating the minimize-impact requirement.

Community Discussion (6 comments)

m_ch333 👍 1 Selected: AB
B. - ATP checks email and password combinations against its stolen credential database, which is updated regularly as new leaked credentials are found on the dark web - ATP can temporarily block client sessions or IP addresses that have too many login failures - AWS WAF performs response inspection asynchronously, so this doesn't increase latency in your web traffic https://docs.aws.amazon.com/waf/latest/developerguide/aws-managed-rule-groups-atp.html
Pmktechno 👍 1 Selected: AB
Answer A and B
Curl8012 👍 3 Selected: BE
B - This satisfy the requirement to reduce the chance of stuffing attack E - This satisfy the requirement to minimize impact on legitimate users, as they prevent legit users who may be part of a credential stuffing attack (due to their compromised credentials) from being permanently blocked A leverage Cloudwatch, which is only suitable for monitoring. It goes with D, but option D which block access from IP with multiple success logins will affect legit users more than bad actors. Similarly, setting default CAPTCHA in option C will create more friction to legit users more than mitigating the issue.
IPLogic 👍 2 Selected: AB
Explanation: By monitoring and analyzing successful login attempts from individual IP addresses, you can detect patterns that suggest credential stuffing. This allows you to take targeted actions against suspicious IPs, improving security without impacting legitimate users. B. Add the account takeover prevention (ATP) AWS managed rule group to the web ACL. Configure the rule group to inspect login requests to the system. Block any requests that have the awswaf:managed:aws:atp:signal:credential_compromised label. Explanation: This managed rule group specifically targets account takeover attempts, including credential stuffing. By automatically inspecting and blocking compromised login requests, you add a critical layer of defense without disrupting legitimate user access.
HappyG 👍 1 Selected: AB
Option B: Adding the AWS managed rule group for account takeover prevention (ATP) is a highly effective approach. This rule group is specifically designed to detect and mitigate credential stuffing attacks. It can inspect login attempts, and when it detects a potential compromise based on exposed credentials (indicated by the label awswaf:managed:aws:atp:signal:credential_compromised), it blocks the request. This action directly addresses the security concern while minimizing the impact on legitimate users. Option A: By creating a custom CloudWatch metric to track successful login attempts from a single IP address, you can proactively monitor and detect patterns indicative of a credential stuffing attack (such as a high volume of successful logins from one source). This allows you to implement additional measures (e.g., blocking or rate-limiting) based on the analysis of this metric without affecting legitimate users.
jdx000 👍 1 Selected: BD
I think b and d

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

B adds the ATP managed rule group, which inspects login traffic against AWS's compromised-credential database and labels credential_compromised attempts so they can be blocked—directly reducing successful credential stuffing. E adds a custom block response that sends flagged users into a secure password-reset workflow, so legitimate users whose credentials appeared in breaches are helped rather than permanently blocked, satisfying the minimize-impact requirement. Together they meet both stated goals.

Why the Other Options Are Wrong

A (CloudWatch custom metric) is analysis only; it does not prevent attacks or protect users at the WAF. C (default CAPTCHA for all logins) hampers every legitimate user, contradicting the minimize-impact goal. D (block IPs with many successful logins) risks blocking shared-NAT legitimate users and does not specifically counter stolen-credential stuffing. B+E is the pair that addresses both requirements.

Community Comment Notes

Community voted A,B (56) and B,E (33). The stronger reasoning favors B,E: B is the core mitigation and E specifically minimizes legitimate-user impact via reset redirect, while A is only monitoring. A minority argued AB, but A does not reduce attacks or protect users; E fulfills the second requirement directly.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide