CLF-C02 Security and Compliance Practice Question
A company runs an e-commerce website on AWS and expects a high volume of traffic during Black Friday. The security team is concerned about potential DDoS attacks overwhelming the infrastructure. The company wants a managed service that provides always-on detection and automatic inline mitigation of DDoS attacks at the network and transport layers (layer 3 and 4), as well as cost protection against scaling charges due to DDoS attacks. Which AWS service should the company use?
⚠ Common exam trap
Many exam-takers confuse AWS Shield Standard (free, basic protection) with AWS Shield Advanced (paid, enhanced protection) or mistakenly think AWS WAF can mitigate network-layer DDoS attacks, when in fact WAF only handles application-layer threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Shield Advanced
AWS Shield Advanced is the correct choice because it provides always-on detection and automatic inline mitigation of DDoS attacks at layers 3 and 4 (network and transport layers), such as SYN floods and UDP reflection attacks. Additionally, it offers cost protection against scaling charges incurred due to DDoS-related usage spikes, which directly addresses the company's concern about financial impact from attack-induced scaling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Shield Standard
Why it's wrong here
AWS Shield Standard is free and provides basic network-layer DDoS protection for all AWS customers, but it does not offer cost protection against scaling charges, nor does it include 24/7 access to a DDoS response team (DRT) or enhanced support. The scenario requires cost protection, which is only available with AWS Shield Advanced.
When this WOULD be correct
A company wants basic DDoS protection for their AWS resources at no additional cost, and they are not concerned about cost protection or access to the DDoS Response Team (DRT). The question would specify 'basic protection' or 'no additional cost' as key constraints.
- ✓
AWS Shield Advanced
Why this is correct
AWS Shield Advanced provides always-on detection and automatic inline mitigation of DDoS attacks at layers 3 and 4 (and layer 7 when integrated with AWS WAF). It also includes cost protection that provides financial coverage against scaling charges (e.g., from EC2 or ELB) incurred during a DDoS attack, as well as 24/7 access to the DDoS Response Team (DRT). This matches all the specified requirements.
- ✗
AWS WAF
Why it's wrong here
AWS WAF is a web application firewall that protects against layer 7 attacks (e.g., SQL injection, cross-site scripting) by inspecting HTTP/HTTPS requests. It does not provide mitigation at the network or transport layers (layer 3/4), nor does it offer cost protection against scaling charges.
When this WOULD be correct
A company needs to protect a web application from common web exploits like SQL injection or cross-site scripting (XSS) at the application layer, and requires customizable rules to filter HTTP requests.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a continuous threat detection service that analyzes AWS CloudTrail, VPC Flow Logs, and DNS logs to identify malicious activity. It does not automatically mitigate DDoS attacks and does not provide cost protection. It would alert on potential attacks but not block them inline.
When this WOULD be correct
A company wants a managed threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads, using machine learning and threat intelligence. The service should generate findings for suspicious API calls, potentially compromised instances, or reconnaissance activity, without requiring manual intervention for detection.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS Shield AdvancedCorrect answer▾
Why this is correct
AWS Shield Advanced provides always-on detection and automatic inline mitigation of DDoS attacks at layers 3 and 4 (and layer 7 when integrated with AWS WAF). It also includes cost protection that provides financial coverage against scaling charges (e.g., from EC2 or ELB) incurred during a DDoS attack, as well as 24/7 access to the DDoS Response Team (DRT). This matches all the specified requirements.
✗AWS Shield StandardWrong answer — click to see why▾
Why this is wrong here
AWS Shield Standard provides always-on detection and automatic inline mitigation for network and transport layer DDoS attacks, but it does not offer cost protection against scaling charges due to DDoS attacks. The question specifically requires cost protection, which is only available with Shield Advanced.
★ When this WOULD be the correct answer
A company wants basic DDoS protection for their AWS resources at no additional cost, and they are not concerned about cost protection or access to the DDoS Response Team (DRT). The question would specify 'basic protection' or 'no additional cost' as key constraints.
Why candidates choose this
Candidates may confuse Shield Standard with Shield Advanced because both provide network and transport layer protection, and the term 'always-on detection' is associated with Shield Standard, leading them to overlook the cost protection requirement.
✗AWS WAFWrong answer — click to see why▾
Why this is wrong here
AWS WAF operates at Layer 7 (application layer) and is not designed for automatic inline mitigation of network/transport layer DDoS attacks, nor does it provide cost protection against scaling charges.
★ When this WOULD be the correct answer
A company needs to protect a web application from common web exploits like SQL injection or cross-site scripting (XSS) at the application layer, and requires customizable rules to filter HTTP requests.
Why candidates choose this
Candidates may confuse WAF as a general DDoS protection service because it can mitigate some application-layer DDoS attacks, but they overlook that the question specifies Layer 3/4 protection and cost protection.
✗Amazon GuardDutyWrong answer — click to see why▾
Why this is wrong here
Amazon GuardDuty is a threat detection service that monitors for malicious activity, but it does not provide automatic inline mitigation of DDoS attacks or cost protection against scaling charges. It operates at the network and account level, not as a dedicated DDoS mitigation service.
★ When this WOULD be the correct answer
A company wants a managed threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads, using machine learning and threat intelligence. The service should generate findings for suspicious API calls, potentially compromised instances, or reconnaissance activity, without requiring manual intervention for detection.
Why candidates choose this
Candidates may confuse GuardDuty's threat detection capabilities with DDoS mitigation, assuming that detecting malicious traffic implies automatic mitigation. They might also think GuardDuty's integration with AWS Shield or WAF provides inline mitigation, but GuardDuty itself does not block attacks.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.