Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company runs an e-commerce website on AWS and expects a high volume of traffic during Black Friday. The security team is concerned about potential DDoS attacks overwhelming the infrastructure. The company wants a managed service that provides always-on detection and automatic inline mitigation of DDoS attacks at the network and transport layers (layer 3 and 4), as well as cost protection against scaling charges due to DDoS attacks. Which AWS service should the company use?

⚠ Common exam trap

Many exam-takers confuse AWS Shield Standard (free, basic protection) with AWS Shield Advanced (paid, enhanced protection) or mistakenly think AWS WAF can mitigate network-layer DDoS attacks, when in fact WAF only handles application-layer threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Shield Advanced

AWS Shield Advanced is the correct choice because it provides always-on detection and automatic inline mitigation of DDoS attacks at layers 3 and 4 (network and transport layers), such as SYN floods and UDP reflection attacks. Additionally, it offers cost protection against scaling charges incurred due to DDoS-related usage spikes, which directly addresses the company's concern about financial impact from attack-induced scaling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Shield Standard

    Why it's wrong here

    AWS Shield Standard is free and provides basic network-layer DDoS protection for all AWS customers, but it does not offer cost protection against scaling charges, nor does it include 24/7 access to a DDoS response team (DRT) or enhanced support. The scenario requires cost protection, which is only available with AWS Shield Advanced.

    When this WOULD be correct

    A company wants basic DDoS protection for their AWS resources at no additional cost, and they are not concerned about cost protection or access to the DDoS Response Team (DRT). The question would specify 'basic protection' or 'no additional cost' as key constraints.

  • AWS Shield Advanced

    Why this is correct

    AWS Shield Advanced provides always-on detection and automatic inline mitigation of DDoS attacks at layers 3 and 4 (and layer 7 when integrated with AWS WAF). It also includes cost protection that provides financial coverage against scaling charges (e.g., from EC2 or ELB) incurred during a DDoS attack, as well as 24/7 access to the DDoS Response Team (DRT). This matches all the specified requirements.

  • AWS WAF

    Why it's wrong here

    AWS WAF is a web application firewall that protects against layer 7 attacks (e.g., SQL injection, cross-site scripting) by inspecting HTTP/HTTPS requests. It does not provide mitigation at the network or transport layers (layer 3/4), nor does it offer cost protection against scaling charges.

    When this WOULD be correct

    A company needs to protect a web application from common web exploits like SQL injection or cross-site scripting (XSS) at the application layer, and requires customizable rules to filter HTTP requests.

  • Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a continuous threat detection service that analyzes AWS CloudTrail, VPC Flow Logs, and DNS logs to identify malicious activity. It does not automatically mitigate DDoS attacks and does not provide cost protection. It would alert on potential attacks but not block them inline.

    When this WOULD be correct

    A company wants a managed threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads, using machine learning and threat intelligence. The service should generate findings for suspicious API calls, potentially compromised instances, or reconnaissance activity, without requiring manual intervention for detection.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS Shield AdvancedCorrect answer

Why this is correct

AWS Shield Advanced provides always-on detection and automatic inline mitigation of DDoS attacks at layers 3 and 4 (and layer 7 when integrated with AWS WAF). It also includes cost protection that provides financial coverage against scaling charges (e.g., from EC2 or ELB) incurred during a DDoS attack, as well as 24/7 access to the DDoS Response Team (DRT). This matches all the specified requirements.

AWS Shield StandardWrong answer — click to see why

Why this is wrong here

AWS Shield Standard provides always-on detection and automatic inline mitigation for network and transport layer DDoS attacks, but it does not offer cost protection against scaling charges due to DDoS attacks. The question specifically requires cost protection, which is only available with Shield Advanced.

★ When this WOULD be the correct answer

A company wants basic DDoS protection for their AWS resources at no additional cost, and they are not concerned about cost protection or access to the DDoS Response Team (DRT). The question would specify 'basic protection' or 'no additional cost' as key constraints.

Why candidates choose this

Candidates may confuse Shield Standard with Shield Advanced because both provide network and transport layer protection, and the term 'always-on detection' is associated with Shield Standard, leading them to overlook the cost protection requirement.

AWS WAFWrong answer — click to see why

Why this is wrong here

AWS WAF operates at Layer 7 (application layer) and is not designed for automatic inline mitigation of network/transport layer DDoS attacks, nor does it provide cost protection against scaling charges.

★ When this WOULD be the correct answer

A company needs to protect a web application from common web exploits like SQL injection or cross-site scripting (XSS) at the application layer, and requires customizable rules to filter HTTP requests.

Why candidates choose this

Candidates may confuse WAF as a general DDoS protection service because it can mitigate some application-layer DDoS attacks, but they overlook that the question specifies Layer 3/4 protection and cost protection.

Amazon GuardDutyWrong answer — click to see why

Why this is wrong here

Amazon GuardDuty is a threat detection service that monitors for malicious activity, but it does not provide automatic inline mitigation of DDoS attacks or cost protection against scaling charges. It operates at the network and account level, not as a dedicated DDoS mitigation service.

★ When this WOULD be the correct answer

A company wants a managed threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads, using machine learning and threat intelligence. The service should generate findings for suspicious API calls, potentially compromised instances, or reconnaissance activity, without requiring manual intervention for detection.

Why candidates choose this

Candidates may confuse GuardDuty's threat detection capabilities with DDoS mitigation, assuming that detecting malicious traffic implies automatic mitigation. They might also think GuardDuty's integration with AWS Shield or WAF provides inline mitigation, but GuardDuty itself does not block attacks.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.