A legitimate lock-form POST trips a managed SQL-injection rule, and a contractor wants the entire WAF policy disabled. What should the security engineer do?
Select an answer to reveal the explanation.
Short Explanation
One noisy form field isn’t a reason to shut the WAF off. Carve a custom rule or managed-rule exclusion for that path, keep Prevention humming, and move on.
Full Explanation
When a legitimate request hits a managed rule, the correct tuning is a custom rule or a managed-rule exclusion scoped to the path or parameter, while leaving Prevention enabled. Disabling the whole WAF policy removes protection for the site. Broad permanent Detection without fixing the false positive leaves blocking off. Removing the WAF host platform avoids the tuning task rather than solving it. Catalog dumps of OWASP CRS rule IDs are unnecessary for this judgment item.