Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company runs a web application on EC2 behind an Application Load Balancer (ALB). They want to protect against SQL injection and cross-site scripting (XSS) attacks. Which AWS service should they use?

⚠ Common exam trap

Many candidates confuse network-layer controls (security groups, NACLs) or DDoS protection (Shield) with application-layer filtering, failing to recognize that only a web application firewall like AWS WAF can inspect HTTP payloads for injection attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy AWS WAF in front of the ALB and create rules to block SQL injection and XSS.

AWS WAF is a web application firewall that integrates directly with Application Load Balancers to inspect HTTP/HTTPS requests for common attack patterns. It provides managed rule sets specifically designed to block SQL injection and cross-site scripting (XSS) attacks at the application layer, which is exactly what this scenario requires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure security groups to allow only HTTP/HTTPS traffic.

    Why it's wrong here

    Security groups function as a stateful virtual firewall at the instance or ENI level and make allow/deny decisions based on source/destination IP addresses, ports, and protocols. They cannot inspect HTTP headers, query strings, or request bodies, so SQL injection and XSS payloads carried inside legitimate HTTPS requests on port 443 will pass through untouched. Restricting the ALB's security group to only HTTP/HTTPS merely controls which ports are reachable, not whether the application-layer content is malicious.

  • ✗

    Configure network ACLs to block common attack patterns based on IP ranges.

    Why it's wrong here

    Network ACLs are stateless per-subnet firewall rules that evaluate traffic only against IP address, port number, and protocol fields. They cannot parse HTTP request attributes such as URI, headers, or body that are needed to detect SQLi or XSS. Even if you add rules to deny known malicious source IP ranges, attackers can easily rotate origins, and common attack patterns are signature-based, not IP-based. Also, because NACLs are stateless, you must configure both inbound and outbound rules, but that still doesn't enable application-layer inspection.

  • ✓

    Deploy AWS WAF in front of the ALB and create rules to block SQL injection and XSS.

    Why this is correct

    AWS WAF is an application-layer firewall that can be associated with an Application Load Balancer and inspects each HTTP/HTTPS request for suspicious patterns. You can create custom rules and use AWS-managed rule groups such as AWSManagedRulesSQLiRuleSet and AWSManagedRulesCommonRuleSet to automatically block SQL injection, cross-site scripting, and other common web exploits. These rules evaluate request components like headers, query strings, body, and cookies, which is exactly what is needed to stop these attacks before they reach the EC2 instances.

  • ✗

    Enable AWS Shield Advanced to protect the ALB.

    Why it's wrong here

    AWS Shield Advanced is a managed Distributed Denial of Service (DDoS) protection service that provides always-on network and transport layer monitoring and mitigates volumetric attacks. It offers enhanced detection, DDoS cost protection, and access to the DDoS Response Team, but its core function is not blocking SQL injection or XSS. While Shield Advanced can be paired with AWS WAF for broader layer 7 DDoS mitigation, deploying Shield alone to the ALB will not evaluate HTTP application payloads and therefore will not protect against injection-based attacks.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.