The current placement, at tier "30", causes the exceptions for the AWS CLI (v2) to be inserted before "Core ELF rules" (in tier "40") as well as the scripted-languages rules (at tier "70"). The rule-group should be moved to tier "80" to make resulting systems more secure.
From the vendor documentation for fapolicyd:

The current placement, at tier "30", causes the exceptions for the AWS CLI (v2) to be inserted before "Core ELF rules" (in tier "40") as well as the scripted-languages rules (at tier "70"). The rule-group should be moved to tier "80" to make resulting systems more secure.
From the vendor documentation for fapolicyd: