Courseiva
Security →easyMultiple Select

DVA-C02 AWS WAF Practice Question

Which TWO AWS services can be used to protect an application running on EC2 from common web exploits like SQL injection and cross-site scripting?

⚠ Common exam trap

Many candidates confuse AWS Shield Advanced (a DDoS protection service) with application-layer protection, mistakenly believing it can block web exploits like SQL injection and XSS, when in fact it focuses on volumetric DDoS attacks and does not inspect HTTP payload content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF

AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting by inspecting HTTP(S) requests and blocking malicious patterns. AWS Shield Advanced is a DDoS protection service; it does not directly filter for SQL injection or XSS. Therefore, only AWS WAF is the appropriate service for this specific protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch

    Why it's wrong here

    CloudWatch is for monitoring and observability.

  • ✗

    Security Groups

    Why it's wrong here

    Security Groups operate at the network layer, not application layer.

  • ✓

    AWS WAF

    Why this is correct

    AWS WAF is correct because it filters HTTP(S) requests to block SQL injection and cross-site scripting attacks.

  • ✗

    AWS Shield Advanced

    Why it's wrong here

    AWS Shield Advanced provides DDoS protection, not direct protection against SQL injection or XSS, so it is not appropriate for this specific use case.

  • ✗

    AWS Identity and Access Management (IAM)

    Why it's wrong here

    IAM is for managing access to AWS resources.

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.