Courseiva
Security and Compliance →easyMultiple Choice

CLF-C02 Security and Compliance Practice Question

Which AWS service provides a Web Application Firewall that protects web applications from common exploits like SQL injection and cross-site scripting?

⚠ Common exam trap

Candidates often confuse AWS Shield (DDoS protection) with AWS WAF (application-layer filtering), but Shield operates at the network/transport layer while WAF inspects application-layer payloads for exploits like SQL injection and XSS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). It allows you to create custom rules that block, allow, or monitor web requests based on conditions such as IP addresses, HTTP headers, URI strings, and request body content. This makes it the correct service for the described use case.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield is incorrect because it is a managed DDoS protection service that safeguards against volumetric and protocol-based attacks at Layers 3 and 4, such as UDP floods and SYN floods. Shield does not inspect or filter individual web requests for security signature patterns like SQL injection or XSS, which are application-layer threats. While Shield can be paired with WAF, Shield itself has no rule engine for OWASP vulnerabilities.

  • ✓

    AWS WAF

    Why this is correct

    AWS WAF is the correct choice because it is a web application firewall that inspects HTTP and HTTPS requests at Layer 7. It uses web ACLs and rule sets to identify and block SQL injection, cross-site scripting (XSS), and other OWASP Top 10 threats by examining request headers, bodies, and query strings. WAF can also rate-limit or block bad bots via bot control and managed rule groups.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is incorrect because it analyzes telemetry from AWS CloudTrail, VPC flow logs, and DNS logs using machine learning to detect unusual API activity, compromised credentials, or cryptocurrency mining. It does not inspect actual web traffic payloads, so it cannot identify SQL injection or XSS patterns embedded in HTTP requests. GuardDuty detects account-level and network-level anomalies, not application-layer OWASP vulnerabilities.

  • ✗

    Security Groups

    Why it's wrong here

    Security Groups are incorrect because they act as a stateful virtual firewall that filters traffic based only on IP addresses, ports, and protocols. They operate at the network and transport layers (Layers 3 and 4) and have no visibility into the contents of an HTTP request, such as URL paths, query parameters, or body data. Therefore, a security group cannot distinguish a legitimate request from a malicious SQLi or XSS payload.

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.