More Info:

Default Execution Endpoint should not be enabled for your Amazon API Gateway APIs in order to secure your APIs.

Risk Level

Low

Address

Reliability, Security

Compliance Standards

CBP

Triage and Remediation

Check Cause

  1. Sign in to the AWS Management Console and open the Amazon API Gateway console at https://console.aws.amazon.com/apigateway/.

  2. In the navigation pane, choose ‘APIs’.

  3. In the APIs pane, select the API you want to check.

  4. In the API details pane, choose ‘Stages’.

  5. In the Stages pane, select the stage you want to check. If the ‘Invoke URL’ ends with /{proxy}, the Default Execution Endpoint is enabled.

Additional Reading: