Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A company runs a web application on EC2 instances behind an Application Load Balancer. The security team discovers that the application is vulnerable to SQL injection attacks. The team wants to implement a web application firewall (WAF) to block these attacks. The architecture includes an ALB, EC2 instances in an Auto Scaling group, and an RDS database. The ALB currently has a listener on port 443 with an SSL certificate. The developer must integrate AWS WAF with minimal changes to the existing infrastructure. Which action should the developer take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Associate AWS WAF directly with the Application Load Balancer.

AWS WAF can be directly associated with an Application Load Balancer (ALB) to filter HTTP/HTTPS requests and block SQL injection attacks. This requires minimal changes to the existing infrastructure because no additional components like CloudFront or agents are needed. Option A is incorrect because AWS Shield Advanced is a DDoS protection service, not a WAF, and does not include SQL injection rules. Option B is incorrect because WAF is a managed service that operates at the edge or load balancer level, not as an agent on EC2 instances. Option C is incorrect because while you could place CloudFront in front of the ALB and attach WAF to CloudFront, it adds unnecessary complexity and cost when the ALB already supports direct WAF association.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Subscribe to AWS Shield Advanced and enable automatic mitigation.

    Why it's wrong here

    AWS Shield Advanced provides enhanced protection against network and transport layer (Layer 3/4) and some application layer (Layer 7) distributed denial-of-service attacks along with cost protection and DDoS response team access, but it does not inspect HTTP request content for injection patterns like SQL injection, which requires the rule-based Layer 7 inspection that only AWS WAF provides.

  • ✗

    Install a WAF agent on each EC2 instance in the Auto Scaling group.

    Why it's wrong here

    AWS WAF is a fully managed, regional or edge-deployed service that attaches to supported resources such as an ALB, API Gateway, AppSync, or CloudFront distribution; it has no software agent or installable component that runs on individual EC2 instances, so there is no WAF agent to install within the Auto Scaling group's instances.

  • ✗

    Place a CloudFront distribution in front of the ALB and associate WAF with CloudFront.

    Why it's wrong here

    Introducing a CloudFront distribution in front of the existing ALB would work technically since WAF also integrates with CloudFront, but it adds an entirely new service, additional caching and origin configuration, and potential changes to how the SSL certificate and DNS are handled, which directly conflicts with the stated goal of minimal changes to the existing infrastructure.

  • ✓

    Associate AWS WAF directly with the Application Load Balancer.

    Why this is correct

    AWS WAF supports direct association with an Application Load Balancer through a web ACL, letting the developer attach managed rule groups such as the SQL injection rule set (AWSManagedRulesSQLiRuleSet) to the existing ALB with no new services, no DNS changes, and no modification to the SSL listener, satisfying the requirement for minimal-change integration.

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.