Attach a web ACL to one entry point
Start with one CloudFront distribution or one application entry point. Avoid changing several AWS front doors in the same experiment.
- The web ACL association is visible.
- Default action is understood.
- Logs are enabled before blocking decisions.