DOP-C02 Incident and Event Response Practice Question
A company is experiencing a DDoS attack on its application hosted on AWS. The application uses an Application Load Balancer (ALB) with an Auto Scaling group of EC2 instances. The security team needs to mitigate the attack with minimal latency impact on legitimate users. Which THREE actions should the team take? (Choose THREE.)
⚠ Common exam trap
Many exam-takers confuse scaling-based absorption (Option D) with actual mitigation, leading candidates to think handling more traffic automatically defends against DDoS, when in reality it only increases cost and resource exhaustion without blocking the attack source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS Shield Advanced on the ALB.
AWS Shield Advanced provides enhanced DDoS mitigation for ALBs, including access to the DDoS Response Team (DRT) and financial protection against scaling costs. It operates at the network and transport layers with minimal latency, as it inspects traffic inline without introducing significant processing delay. This makes it a critical first line of defense for high-availability applications under attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable cross-zone load balancing on the ALB to limit the number of instances receiving traffic.
Why it's wrong here
Disabling cross-zone load balancing confines traffic distribution to each Availability Zone's own targets, but the Application Load Balancer still accepts the full volume of malicious requests and the overall capacity is not reduced. This setting only shifts where requests are forwarded, and in fact can lead to underutilized instances across other AZs, making the application more vulnerable to overload and not addressing the DDoS source.
- ✓
Enable AWS Shield Advanced on the ALB.
Why this is correct
Shield Advanced provides always-on detection and inline mitigation at the AWS edge, absorbing large volumetric DDoS attacks before they reach the ALB. It also includes DDoS cost protection and 24/7 access to the DDoS Response Team (DRT), who can analyze attack patterns and apply mitigations directly. Enabling it on the ALB is a fundamental step for comprehensive DDoS protection.
- ✓
Enable connection draining (deregistration delay) on the ALB target group.
Why this is correct
Connection draining (deregistration delay) ensures that when targets are removed from the ALB rotation—whether during instance replacement or a scale-in event—in-flight requests can complete gracefully. During a DDoS incident, this prevents sudden connection resets for legitimate users and preserves session continuity, which is especially important if you are cycling instances to isolate compromised or unhealthy targets. While it does not stop the attack flood, it reduces the operational disruption caused by defensive actions.
- ✗
Configure the Auto Scaling group to scale based on the NetworkIn metric to handle the increased traffic.
Why it's wrong here
Scaling the Auto Scaling group based on NetworkIn tries to add capacity to absorb malicious traffic, but a DDoS flood will simply consume those additional resources and drive up instance costs without relieving the overload. Because the attack traffic is not legitimate workload, the scale-out policy may chase the attack metrics, repeatedly launching instances and potentially surpassing account limits. High-level mitigation at the edge or WAF is required instead of reactive scaling.
- ✓
Configure AWS WAF on the ALB to block requests based on source IP reputation or rate-based rules.
Why this is correct
Configuring AWS WAF rules on the ALB allows inspection of HTTP(S) requests, enabling rate-based rules to throttle suspicious source IPs and IP reputation filters to block known bad actors. This targets the application-layer DDoS vectors, such as HTTP floods or slow attacks, by rejecting malicious requests before they hit the application servers. WAF complements Shield Advanced by addressing L7 patterns, and can be deployed with managed rule groups for rapid response.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.