DOP-C02 Security and Compliance Practice Question
A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to protect the application from common web exploits like SQL injection and cross-site scripting. Which AWS service should be used?
⚠ Common exam trap
Candidates often confuse AWS WAF with AWS Shield or GuardDuty, mistakenly thinking that DDoS protection or general threat detection covers application-layer attacks like SQL injection and XSS, when in fact only a web application firewall (WAF) can inspect and filter HTTP request payloads at Layer 7.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF
AWS WAF is a web application firewall that helps protect web applications from common web exploits that could affect application availability, compromise security, or consume excessive resources. It allows you to create rules that filter and monitor HTTP(S) requests based on conditions such as IP addresses, HTTP headers, URI strings, and SQL injection or cross-site scripting patterns. By integrating with an Application Load Balancer, AWS WAF can inspect incoming traffic and block malicious requests before they reach the EC2 instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced provides enhanced DDoS protection with 24/7 incident response and cost protection, but it operates primarily at the network and transport layers, focusing on volumetric and state-exhaustion attacks. It does not inspect application-layer traffic for patterns like SQL injection or XSS, and it will not block a malicious HTTP request targeting a web application flaw. Therefore, it cannot protect against the web exploit described in the scenario.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that continuously analyzes VPC Flow Logs, DNS logs, and CloudTrail events to identify suspicious activity, such as compromised EC2 instances or credential abuse. It is a detective control that generates alerts after a potential issue has occurred; it does not actively evaluate or filter incoming web requests in real time. GuardDuty would not prevent a SQL injection or XSS attack at the application layer, as it lacks the ability to inspect and block HTTP payloads before they reach the web server.
- ✗
AWS Network Firewall
Why it's wrong here
AWS Network Firewall is a managed firewall that provides stateful and stateless filtering for VPC traffic at Layer 3 and Layer 4, with some Layer 7 inspection capability via Suricata-compatible rules. However, it is deployed at the subnet or VPC boundary and is not integrated with the application request flow in the same way as a WAF. It cannot selectively parse and block parameter values in HTTP requests for SQLi or XSS, making it unsuitable for protecting a web application from these specific exploits.
- ✓
AWS WAF
Why this is correct
AWS WAF is a web application firewall that integrates directly with an Application Load Balancer to inspect and filter HTTP(S) requests before they are forwarded to your EC2 instances. It provides managed rules specifically designed to detect and block common web exploits, including SQL injection and cross-site scripting, and you can define custom rules to handle unique business logic. This is the appropriate service to stop malicious requests from ever reaching the web server, directly addressing the requirement for protection against web exploits.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.