Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company runs a critical web application on AWS behind an Application Load Balancer. The security team is concerned about the risk of Distributed Denial of Service (DDoS) attacks that could deplete application resources and incur high costs due to auto scaling. The company wants a managed service that provides enhanced DDoS detection, access to the AWS DDoS Response Team (DRT), and financial protection against scaling costs associated with DDoS attacks. Which AWS service should the company use?

⚠ Common exam trap

It's easy for candidates to confuse AWS Shield Standard (free, basic) with AWS Shield Advanced (paid, enhanced) or mistakenly think AWS WAF alone can handle DDoS cost protection and DRT access, when in fact WAF lacks those specific features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Shield Advanced

AWS Shield Advanced is the correct choice because it provides enhanced DDoS detection and mitigation beyond what Shield Standard offers, includes 24/7 access to the AWS DDoS Response Team (DRT) for custom mitigations, and offers financial protection (cost protection) against scaling costs incurred due to DDoS attacks on resources like Application Load Balancers. This directly addresses the company's need for a managed service that covers detection, expert support, and cost coverage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Shield Standard

    Why it's wrong here

    AWS Shield Standard is incorrect for this scenario because, although it is a free, always-on layer that automatically mitigates common network and transport layer DDoS attacks (e.g., SYN floods and UDP amplification), it lacks the advanced features needed for a critical application. It does not provide access to the DDoS Response Team, so you cannot get expert, on-demand support during an attack, nor does it offer cost protection to reimburse you for scaling costs that a DDoS attack may trigger. These gaps make it insufficient for critical production workloads.

    When this WOULD be correct

    A company wants basic, no-cost DDoS protection for its AWS resources without needing advanced features like DRT access or cost protection. The question would specify that the company has a limited budget and only requires baseline protection against common DDoS attacks.

  • AWS Shield Advanced

    Why this is correct

    AWS Shield Advanced is the correct choice because it is AWS's premium DDoS protection service that goes beyond basic mitigation. It provides always-on detection and automatic inline mitigation for sophisticated attacks targeting your critical web application. Crucially, it grants 24/7 access to the AWS DDoS Response Team (DRT) for manual intervention, and it includes financial protection that reimburses you for AWS bill spikes caused by scaling resources during a DDoS attack, which is essential for a critical application.

  • AWS WAF

    Why it's wrong here

    Incorrect. AWS WAF is a web application firewall that helps protect web applications from common exploits like SQL injection or cross-site scripting, but it is not designed for DDoS protection at the network or transport layer.

    When this WOULD be correct

    A company needs to protect a web application from common web exploits like SQL injection or cross-site scripting, and requires customizable rules to block malicious traffic patterns. AWS WAF would be the correct service to use in that scenario.

  • AWS Firewall Manager

    Why it's wrong here

    AWS Firewall Manager is incorrect because it is a security management service, not a DDoS protection engine. It centralizes the creation, deployment, and monitoring of firewall rules (including AWS WAF rules and AWS Shield Advanced protections) across multiple accounts and resources in an AWS Organization. While Firewall Manager can help you enforce Shield Advanced policies, it does not itself absorb or mitigate DDoS traffic; it only orchestrates the configuration of the actual protection services.

    When this WOULD be correct

    A company needs to centrally manage AWS WAF rules, AWS Shield Advanced protections, and VPC security groups across multiple accounts and resources, ensuring consistent security policy enforcement and compliance.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS Shield AdvancedCorrect answer

Why this is correct

AWS Shield Advanced is the correct choice because it is AWS's premium DDoS protection service that goes beyond basic mitigation. It provides always-on detection and automatic inline mitigation for sophisticated attacks targeting your critical web application. Crucially, it grants 24/7 access to the AWS DDoS Response Team (DRT) for manual intervention, and it includes financial protection that reimburses you for AWS bill spikes caused by scaling resources during a DDoS attack, which is essential for a critical application.

AWS Shield StandardWrong answer — click to see why

Why this is wrong here

AWS Shield Standard is a free service that provides basic DDoS protection but lacks enhanced detection, access to the DDoS Response Team (DRT), and financial protection against scaling costs, which are specifically required in the question.

★ When this WOULD be the correct answer

A company wants basic, no-cost DDoS protection for its AWS resources without needing advanced features like DRT access or cost protection. The question would specify that the company has a limited budget and only requires baseline protection against common DDoS attacks.

Why candidates choose this

Candidates may assume Shield Standard is sufficient because it offers DDoS protection, overlooking the specific requirements for enhanced detection, DRT access, and financial protection that only Shield Advanced provides.

AWS WAFWrong answer — click to see why

Why this is wrong here

AWS WAF is a web application firewall that filters and monitors HTTP/S requests, but it does not provide DDoS detection, access to the DDoS Response Team (DRT), or financial protection against scaling costs due to DDoS attacks. These features are exclusive to AWS Shield Advanced.

★ When this WOULD be the correct answer

A company needs to protect a web application from common web exploits like SQL injection or cross-site scripting, and requires customizable rules to block malicious traffic patterns. AWS WAF would be the correct service to use in that scenario.

Why candidates choose this

Candidates may mistakenly believe that AWS WAF includes DDoS protection features because it can block malicious traffic, but it lacks the advanced DDoS mitigation, DRT access, and cost protection provided by Shield Advanced.

AWS Firewall ManagerWrong answer — click to see why

Why this is wrong here

AWS Firewall Manager is a central security management service that helps configure and apply firewall rules across accounts and resources, but it does not provide DDoS detection, access to the DRT, or financial protection against scaling costs from DDoS attacks.

★ When this WOULD be the correct answer

A company needs to centrally manage AWS WAF rules, AWS Shield Advanced protections, and VPC security groups across multiple accounts and resources, ensuring consistent security policy enforcement and compliance.

Why candidates choose this

Candidates may confuse Firewall Manager's centralized security management capabilities with the specific DDoS protection features offered by Shield Advanced, or think it includes DDoS mitigation because it manages Shield Advanced policies.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.