Courseiva
Security and Compliance →easyMultiple Choice

CLF-C02 Security and Compliance Practice Question

What is the purpose of AWS Shield Standard?

⚠ Common exam trap

Watch out — candidates often confuse AWS Shield Standard with AWS WAF, mistakenly thinking Shield Standard provides application-layer filtering (like SQL injection or XSS protection), when in fact it only handles infrastructure-layer DDoS attacks, while WAF is needed for Layer 7 web traffic inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To protect AWS resources against common DDoS attacks

AWS Shield Standard is a free, always-on service that protects all AWS customers from common, infrastructure-layer Distributed Denial of Service (DDoS) attacks, such as SYN floods, UDP floods, and reflection attacks. It uses network flow monitoring and inline mitigation techniques at the AWS edge to automatically detect and block malicious traffic targeting AWS resources like EC2, ELB, CloudFront, and Route 53. This makes option B correct because its sole purpose is to provide baseline DDoS protection without any additional configuration or cost.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To encrypt data at rest in S3 buckets

    Why it's wrong here

    AWS Shield Standard is a DDoS protection service, not an encryption service. S3 data-at-rest encryption is implemented via Server-Side Encryption (SSE) options such as SSE-S3, SSE-KMS, or SSE-C, or via client-side encryption. Shield operates at the network and transport layers to mitigate volumetric attacks and has no capability to encrypt stored objects.

  • ✓

    To protect AWS resources against common DDoS attacks

    Why this is correct

    AWS Shield Standard is the correct answer because it provides automatic, always-on detection and inline mitigation for common Layer 3 and Layer 4 DDoS attacks, including SYN floods, UDP floods, and reflection attacks. This protection is included with all AWS accounts at no additional cost and covers resources such as CloudFront distributions, Elastic Load Balancers, and S3 buckets. Shield Standard runs transparently in the background, so no configuration or management is required.

  • ✗

    To monitor API calls made to AWS services

    Why it's wrong here

    Monitoring API calls is the responsibility of AWS CloudTrail, not Shield. CloudTrail records every API action taken by users, roles, or services, providing an audit log for governance and compliance. AWS Shield Standard is focused solely on mitigating DDoS attacks and does not log or monitor API activity, though it may emit CloudWatch metrics for other purposes.

  • ✗

    To filter malicious web traffic using rules

    Why it's wrong here

    Rule-based filtering of malicious web traffic is provided by AWS WAF, a web application firewall that allows users to define custom rules to block or allow requests based on IP, HTTP headers, URI strings, or known attack signatures. AWS Shield Standard, in contrast, automatically mitigates common DDoS attacks without any user-defined rules or configuration. To customize filtering, customers must deploy AWS WAF alongside Shield (Advanced version often included) for application-layer protection.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.