CLF-C02 Security and Compliance Practice Question
Which AWS service provides a Web Application Firewall that protects web applications from common exploits like SQL injection and cross-site scripting?
⚠ Common exam trap
Candidates often confuse AWS Shield (DDoS protection) with AWS WAF (application-layer filtering), but Shield operates at the network/transport layer while WAF inspects application-layer payloads for exploits like SQL injection and XSS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF
AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). It allows you to create custom rules that block, allow, or monitor web requests based on conditions such as IP addresses, HTTP headers, URI strings, and request body content. This makes it the correct service for the described use case.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Shield
Why it's wrong here
AWS Shield is incorrect because it is a managed DDoS protection service that safeguards against volumetric and protocol-based attacks at Layers 3 and 4, such as UDP floods and SYN floods. Shield does not inspect or filter individual web requests for security signature patterns like SQL injection or XSS, which are application-layer threats. While Shield can be paired with WAF, Shield itself has no rule engine for OWASP vulnerabilities.
- ✓
AWS WAF
Why this is correct
AWS WAF is the correct choice because it is a web application firewall that inspects HTTP and HTTPS requests at Layer 7. It uses web ACLs and rule sets to identify and block SQL injection, cross-site scripting (XSS), and other OWASP Top 10 threats by examining request headers, bodies, and query strings. WAF can also rate-limit or block bad bots via bot control and managed rule groups.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is incorrect because it analyzes telemetry from AWS CloudTrail, VPC flow logs, and DNS logs using machine learning to detect unusual API activity, compromised credentials, or cryptocurrency mining. It does not inspect actual web traffic payloads, so it cannot identify SQL injection or XSS patterns embedded in HTTP requests. GuardDuty detects account-level and network-level anomalies, not application-layer OWASP vulnerabilities.
- ✗
Security Groups
Why it's wrong here
Security Groups are incorrect because they act as a stateful virtual firewall that filters traffic based only on IP addresses, ports, and protocols. They operate at the network and transport layers (Layers 3 and 4) and have no visibility into the contents of an HTTP request, such as URL paths, query parameters, or body data. Therefore, a security group cannot distinguish a legitimate request from a malicious SQLi or XSS payload.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.