CLF-C02 Security and Compliance Practice Question
What is the purpose of AWS Shield Standard?
⚠ Common exam trap
Watch out — candidates often confuse AWS Shield Standard with AWS WAF, mistakenly thinking Shield Standard provides application-layer filtering (like SQL injection or XSS protection), when in fact it only handles infrastructure-layer DDoS attacks, while WAF is needed for Layer 7 web traffic inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To protect AWS resources against common DDoS attacks
AWS Shield Standard is a free, always-on service that protects all AWS customers from common, infrastructure-layer Distributed Denial of Service (DDoS) attacks, such as SYN floods, UDP floods, and reflection attacks. It uses network flow monitoring and inline mitigation techniques at the AWS edge to automatically detect and block malicious traffic targeting AWS resources like EC2, ELB, CloudFront, and Route 53. This makes option B correct because its sole purpose is to provide baseline DDoS protection without any additional configuration or cost.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To encrypt data at rest in S3 buckets
Why it's wrong here
AWS Shield Standard is a DDoS protection service, not an encryption service. S3 data-at-rest encryption is implemented via Server-Side Encryption (SSE) options such as SSE-S3, SSE-KMS, or SSE-C, or via client-side encryption. Shield operates at the network and transport layers to mitigate volumetric attacks and has no capability to encrypt stored objects.
- ✓
To protect AWS resources against common DDoS attacks
Why this is correct
AWS Shield Standard is the correct answer because it provides automatic, always-on detection and inline mitigation for common Layer 3 and Layer 4 DDoS attacks, including SYN floods, UDP floods, and reflection attacks. This protection is included with all AWS accounts at no additional cost and covers resources such as CloudFront distributions, Elastic Load Balancers, and S3 buckets. Shield Standard runs transparently in the background, so no configuration or management is required.
- ✗
To monitor API calls made to AWS services
Why it's wrong here
Monitoring API calls is the responsibility of AWS CloudTrail, not Shield. CloudTrail records every API action taken by users, roles, or services, providing an audit log for governance and compliance. AWS Shield Standard is focused solely on mitigating DDoS attacks and does not log or monitor API activity, though it may emit CloudWatch metrics for other purposes.
- ✗
To filter malicious web traffic using rules
Why it's wrong here
Rule-based filtering of malicious web traffic is provided by AWS WAF, a web application firewall that allows users to define custom rules to block or allow requests based on IP, HTTP headers, URI strings, or known attack signatures. AWS Shield Standard, in contrast, automatically mitigates common DDoS attacks without any user-defined rules or configuration. To customize filtering, customers must deploy AWS WAF alongside Shield (Advanced version often included) for application-layer protection.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.