5.4 Edge Integrations: Managed Rule Groups, OCSF Ingestion, IoT Policies & CORS

Key Takeaways

  • AWS WAF web ACLs can include AWS managed rule groups and third-party rule groups from AWS Marketplace; test new groups by overriding rule actions to Count.

  • AWS WAF logging destinations must be named with the aws-waf-logs- prefix, and Firehose can forward logs to third-party SIEMs.

  • Security Lake ingests AWS WAF logs natively in OCSF, while third-party custom sources must write OCSF records in Parquet format.

  • AWS IoT Core policies with variables such as iot:Connection.Thing.ThingName scope one policy to each device's own client ID and topics.

  • S3 CORS configuration is not authorization; wildcard origins let any website drive cross-origin requests from a user's browser.

Last updated: September 2026

5.4 Edge Integrations: Managed Rule Groups, OCSF Ingestion, IoT Policies & CORS

SCS-C03 Skill 3.1.4 asks you to integrate AWS edge services with third-party services, for example by using third-party WAF rules and ingesting data in Open Cybersecurity Schema Framework (OCSF) format. Skill 3.1.2 also lists edge controls that don't fit neatly into CloudFront or AWS WAF alone: AWS IoT policies and Amazon S3 cross-origin resource sharing (CORS). This section covers those integrations.


Managed Rule Groups: AWS and Third-Party

AWS WAF web ACLs can combine your own rules with managed rule groups maintained by someone else.

Rule Group SourceExamplesNotes
AWS Managed RulesCore rule set, Known bad inputs, SQL database, Linux and POSIX operating system, PHP and WordPress application, Amazon IP reputation list, Anonymous IP listMost are included in AWS WAF pricing
AWS Managed Rules (paid features)Bot Control, Account Takeover Prevention (ATP), Account Creation Fraud Prevention (ACFP)Extra fees; use scope-down statements to inspect only relevant requests, such as login paths
AWS Marketplace sellersRule groups from security vendors (for example, OWASP-focused or bot-management sets)Subscribe in AWS Marketplace, then add to the web ACL; the vendor updates the rules

Operating managed rule groups well:

  • Test before blocking: Override a new rule group's rule actions to Count, review the WAF logs and labels, then switch to the vendor's actions.
  • Use labels: Managed rules add labels (for example, awswaf:managed:aws:bot-control:bot:category:...). Later rules in the web ACL can match on labels to build logic such as "block this bot category only on the checkout path."
  • Control versions: AWS managed rule groups can be pinned to a static version and subscribed to SNS notifications about new versions, so updates don't surprise production.
  • Budget capacity: Every rule group consumes web ACL capacity units (WCUs). Vendor rule groups can't be edited, but individual rules can be overridden.
  • Deploy centrally: AWS Firewall Manager can push a web ACL containing AWS and Marketplace rule groups to every account in an organization.

Client Fingerprinting at the Edge

AWS WAF can match the JA3 and JA4 TLS client fingerprints of requests to CloudFront distributions and Application Load Balancers. A fingerprint identifies the TLS client software regardless of the source IP address, so a botnet rotating through thousands of IP addresses can still be blocked if its client library produces a consistent fingerprint. Combine fingerprint matches with rate-based rules and Bot Control labels rather than relying on any single signal.


Sending Edge Data to Third-Party Tools and OCSF

Edge telemetry is most useful when it reaches the tools your security operations center already uses.

  • AWS WAF logging destinations are a CloudWatch Logs log group, an S3 bucket, or an Amazon Data Firehose stream, and each destination name must start with aws-waf-logs-. Firehose can deliver to third-party SIEM destinations such as Splunk, Datadog, or an HTTP endpoint.
  • Amazon Security Lake collects AWS WAF logs as a native source and converts them to OCSF, alongside CloudTrail, VPC Flow Logs, Route 53 Resolver query logs, and Security Hub findings. Subscribers such as a SIEM receive the normalized data through S3 access or Lake Formation-based query access.
  • Third-party edge data, such as logs from a third-party CDN, WAF, or firewall, can be added to Security Lake as a custom source. The provider must write records in OCSF format as Apache Parquet files to the custom source's S3 location; Security Lake creates the Glue crawler and IAM role that register the data.
  • CloudFront standard logs can be delivered to CloudWatch Logs, Firehose, or S3, which lets the same pipelines handle CDN access logs.

Normalizing to OCSF means a detection written against src_endpoint.ip works whether the event came from AWS WAF, a VPC Flow Log, or a partner firewall.


AWS IoT Core Policies

Internet of Things devices connect to AWS IoT Core at the edge of your environment, usually over MQTT with mutual TLS and an X.509 client certificate. AWS IoT Core policies (separate from IAM policies) are attached to the device certificate, a thing group, or an Amazon Cognito identity, and they authorize MQTT actions:

ActionResource TypePurpose
iot:Connectclient/<client-id>Connect with a specific MQTT client ID
iot:Publishtopic/<topic-name>Publish to a topic
iot:Subscribetopicfilter/<topic-filter>Subscribe to a topic filter
iot:Receivetopic/<topic-name>Receive messages delivered on a topic

The key least-privilege technique is policy variables, which scope one policy to many devices:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "iot:Connect",
      "Resource": "arn:aws:iot:us-east-1:111122223333:client/${iot:Connection.Thing.ThingName}"
    },
    {
      "Effect": "Allow",
      "Action": "iot:Publish",
      "Resource": "arn:aws:iot:us-east-1:111122223333:topic/devices/${iot:Connection.Thing.ThingName}/telemetry"
    }
  ]
}

Each device may connect only with its own thing name as the client ID and publish only to its own telemetry topic, so one stolen certificate can't impersonate other devices. AWS IoT Device Defender audits for overly permissive policies, shared certificates, and revoked or expiring certificates, and its detect feature flags unusual device behavior.


Amazon S3 Cross-Origin Resource Sharing (CORS)

Browsers block a web page on one origin from reading responses from another origin unless the response includes CORS headers. An S3 CORS configuration lists rules with AllowedOrigins, AllowedMethods, AllowedHeaders, ExposeHeaders, and MaxAgeSeconds.

Two security points matter for the exam:

  1. CORS is not access control. It tells browsers which cross-origin reads to allow; it doesn't stop a direct request from a script or the AWS CLI. Protect the data with bucket policies, Block Public Access, CloudFront origin access control, and presigned URLs.
  2. Keep origins specific. "AllowedOrigins": ["*"] combined with methods such as PUT lets any website drive a user's browser to upload using the user's own presigned URLs or cookies. List exact origins, such as https://app.example.com.

When CloudFront fronts the bucket, forward the Origin header through an origin request policy (or a managed CORS policy) and, if needed, add CORS headers with a response headers policy. Otherwise the cached response may not include the headers the browser expects.


Specialty Exam Pitfalls

  1. Blocking with an untested vendor rule group: Start new managed rule groups in Count mode to avoid blocking legitimate traffic.
  2. Wrong WAF log destination name: Log groups, buckets, and Firehose streams for AWS WAF logs must be named with the aws-waf-logs- prefix.
  3. Custom Security Lake sources in raw JSON: Custom sources must provide OCSF data in Parquet.
  4. One broad IoT policy for all devices: Use policy variables so each certificate can act only as its own thing.
  5. Treating CORS as authorization: CORS relaxes browser restrictions; it never protects data from direct requests.
Loading diagram...
Edge Integrations with Third-Party Tools, IoT, and OCSF
Test Your Knowledge

A company adds a third-party managed rule group from an AWS Marketplace seller to the AWS WAF web ACL on its production CloudFront distribution. The security team wants to confirm the rules won't block legitimate customers before enforcing them. What should the team do?

A

Copy the vendor's rules into a custom rule group so they can be edited.

B

Override the rule group's rule actions to Count, review the AWS WAF logs and labels for matched requests, then remove the override.

C

Attach the rule group to a staging web ACL in a different Region and compare traffic volumes.

D

Set the web ACL default action to Block while testing.

Test Your Knowledge

A security operations team uses a third-party SIEM. It wants AWS WAF logs, CloudTrail management events, and logs from a partner's on-premises firewall normalized into one schema so that detections can match on the same field names. Which approach meets this requirement with the least custom transformation code?

A

Enable Amazon Security Lake with AWS WAF logs and CloudTrail as native sources, add the partner firewall as a custom source that writes OCSF records in Parquet, and grant the SIEM subscriber access.

B

Send each source to a different CloudWatch Logs log group and export them to the SIEM weekly.

C

Write a Lambda function per source that converts records to the SIEM vendor's proprietary format.

D

Enable AWS WAF logging to an S3 bucket named security-waf-logs and point the SIEM at it.

Test Your Knowledge

A manufacturer connects 40,000 sensors to AWS IoT Core. Each sensor has its own X.509 certificate and must publish only to its own telemetry topic. The security team wants to avoid creating 40,000 separate policies. Which IoT Core policy design meets these requirements?

A

An IAM policy attached to each certificate that allows iot:* on all topics.

B

One IoT policy that allows iot:Publish on topic/devices/+/telemetry for every device.

C

One IoT policy that uses the iot:Connection.Thing.ThingName policy variable in the client and topic ARNs, attached to every device certificate.

D

A security group that allows MQTT traffic only from the sensors' IP addresses.

Test Your Knowledge

A single-page application at https://app.example.com uploads files directly to an S3 bucket by using presigned URLs. A developer set the bucket's CORS configuration to AllowedOrigins '*' with PUT and GET methods and argues that this is safe because the bucket blocks public access. What is the most accurate assessment?

A

The configuration is safe, because CORS rules are ignored when Block Public Access is enabled.

B

The configuration makes the bucket publicly writable to anyone on the internet.

C

The configuration is required, because presigned URLs never work without a wildcard origin.

D

CORS isn't an authorization control, but the wildcard lets any website's scripts use a victim's presigned URLs from the browser; the rule should list only https://app.example.com.

Sections you finish are checked off in the contents.