Courseiva
Security and Compliance →easyMultiple Choice

CLF-C02 Security and Compliance Practice Question

A company's public-facing web application is being attacked with SQL injection and cross-site scripting (XSS) attempts. Which AWS service should they deploy to detect and block these web application attacks?

⚠ Common exam trap

It's easy for candidates to confuse AWS Shield (DDoS protection) with AWS WAF (web application firewall), but Shield operates at Layer 3/4 and cannot inspect or block application-layer payloads like SQL injection or XSS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). It allows you to create custom rules to filter and monitor HTTP(S) requests based on conditions such as IP addresses, HTTP headers, or request body patterns, and can block malicious traffic before it reaches your application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Shield Standard

    Why it's wrong here

    AWS Shield Standard is a always-on, managed DDoS protection service that defends AWS customers against common network and transport layer attacks, such as SYN floods, UDP amplification, and reflection attacks. It operates at layers 3 and 4 of the OSI model, using traffic metadata and volumetric analysis to drop malicious traffic at the network edge. However, it does not perform deep packet inspection of application-layer HTTP content, so it has no visibility into SQL injection or XSS syntax and cannot distinguish a legitimate request from one carrying a malicious payload.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a continuous threat detection service that ingests and analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS query logs. It uses anomaly detection and threat intelligence to identify compromised credentials, unusual API patterns, and host or network behavior that may indicate an attack. GuardDuty operates as a security monitoring tool, not as an inline, layer-7 web application firewall; it cannot inspect the content of individual HTTP requests or block SQL injection and XSS attempts in real time.

  • ✓

    AWS WAF

    Why this is correct

    AWS WAF is a web application firewall that operates at layer 7 (HTTP/HTTPS) and is designed to inspect incoming web traffic for malicious payloads. You can attach a web access control list (web ACL) to Application Load Balancer, CloudFront, API Gateway, or App Runner, and use managed rule groups specifically tailored to block SQL injection and cross-site scripting patterns in query strings, URI paths, headers, and request bodies. Because these attacks are differentiated by evaluating request content and structure, AWS WAF is the correct service to actively filter and block them at the edge or application layer before they reach your application.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is an automated vulnerability management service that runs security assessments on Amazon EC2 instances and Amazon ECR container images. It evaluates software configurations, identifies known CVEs in operating systems and packages, and checks for network reachability and unintended exposure using a network assessment agent. These scans are performed on a schedule or triggered by events, not in real time on incoming traffic, so Inspector cannot parse HTTP request bodies or defend against application-layer attacks like SQL injection and XSS.

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.