Mitigate credential stuffing with the WAF ATP rule and a password-reset redirect for affected users
A company has a new web-based account management system for an online game. Players create a unique username and password to log in to the system. The company has implemented an AWS WAF web ACL for the system. The web ACL includes the core rule set (CRS) AWS managed rule group on the Application Load Balancer that serves the system. The company’s security team finds that the system was the target of a credential stuffing attack. Credentials that were exposed in other breaches were used to try to log in to the system. The security team must implement a solution to reduce the chance of a successful credential stuffing attack in the future. The solution also must minimize impact on legitimate users of the system. Which combination of actions will meet these requirements? (Choose two.)
Community Votes
63% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The ATP managed rule group is purpose-built to detect credential stuffing/account takeover using AWS's regularly updated compromised-credential corpus and the credential_compromised label. A password-reset redirect on that label addresses the 'minimize impact on legitimate users' requirement: real users with breached credentials are routed to reset rather than locked out, unlike a hard IP block that harms shared-IP legitimate users.
A WAF with the CRS already fronts the login ALB; the company needs to cut credential-stuffing success and avoid penalizing legitimate users. Adding the AWS WAF account takeover prevention (ATP) managed rule group inspects login requests and emits a credential_compromised label for credentials found in AWS's stolen-credential database, which can be blocked. Pairing it with a custom block response that redirects affected users into a secure password-reset workflow stops attackers while letting legitimate users (whose credentials were in breaches) recover instead of being permanently blocked.
Choosing only a CloudWatch custom metric (option A) for successful-logins-per-IP analysis—that is detection/monitoring, not a WAF prevention action, and does not by itself reduce attacks or protect legitimate users. Or a blanket CAPTCHA default action (option C), which degrades all legitimate users' experience, violating the minimize-impact requirement.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.