Courseiva

CLF-C02 Cloud Technology and Services Practice Question

A company wants to protect their web application from common Layer 7 attacks and also implement rate limiting to prevent API abuse. Which AWS service provides both capabilities?

⚠ Common exam trap

Test-takers frequently confuse AWS Shield (which handles network-layer DDoS) with AWS WAF (which handles application-layer filtering and rate limiting), leading them to select AWS Shield Standard despite it lacking Layer 7 inspection and rate control capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF

AWS WAF is a web application firewall that helps protect web applications from common Layer 7 attacks such as SQL injection and cross-site scripting (XSS). It also supports rate-based rules that automatically block requests from a client IP when the request rate exceeds a defined threshold, enabling API abuse prevention. This makes AWS WAF the correct choice for both capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Shield Standard

    Why it's wrong here

    AWS Shield Standard is a free, always-on protection service that mitigates DDoS attacks at Layers 3 and 4 (network and transport). It works transparently with CloudFront, ALB, and other services, but it cannot inspect HTTP payloads, URI paths, or other application-layer attributes. Because it lacks the ability to create per-IP rate-based rules or filter on HTTP requests, it would not stop a web layer flood or enforce a request threshold.

  • ✓

    AWS WAF

    Why this is correct

    AWS WAF is the correct choice because it operates at the application layer (Layer 7) and offers full visibility into HTTP(S) requests. Administrators can create rate-based rules that automatically count requests from a given IP and trigger a block when the count exceeds a configurable threshold per 5‑minute window. WAF also provides managed rule groups such as OWASP Top 10 and Bot Control, making it easy to protect against HTTP floods, SQL injection, and web scraping without building custom rules from scratch.

  • ✗

    Security Groups

    Why it's wrong here

    Security Groups are virtual firewalls that control inbound and outbound traffic at the instance or elastic network interface level. They evaluate traffic based on the five-tuple of protocol, source/destination IP, source/destination port, and state, but they have no context about HTTP content such as URLs or request headers. Consequently, a security group cannot count how many requests arrive from a specific IP address or apply a rate-based throttle, so it would not mitigate a Layer 7 flood.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is an intelligent threat detection service that continuously analyzes VPC Flow Logs, DNS logs, and CloudTrail events to identify suspicious behavior using machine learning and anomaly detection. While it can surface findings about compromised instances or unusual traffic patterns, it does not process live web requests inline and cannot enforce transformations such as rate limiting or IP blocking. Its purpose is detection and alerting, not proactive prevention at the web application layer, so it would not meet the requirement to cap request rates.

About these practice questions

This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.