Courseiva

DOP-C02 Resilient Cloud Solutions Practice Question

A company wants to protect its application from DDoS attacks. Which THREE AWS services should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF

AWS Shield Advanced, WAF, and CloudFront provide layered DDoS protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is an automated vulnerability management service that continuously scans workloads for software vulnerabilities and unintended network exposure. It generates findings about CVEs and security configuration issues, but it does not inspect live traffic or sit inline in the network path. Because DDoS mitigation requires real-time traffic filtering and absorption, Inspector cannot block or absorb volumetric or application-layer attacks.

  • ✓

    AWS WAF

    Why this is correct

    AWS WAF is a web application firewall that filters and monitors HTTP(S) requests using rules for IP reputation, geographic origin, URI patterns, SQL injection, and cross-site scripting. Its rate-based rules automatically block IPs that exceed configured request thresholds, making it effective against HTTP floods and the low-and-slow application-layer DDoS attacks that target web endpoints. WAF integrates with CloudFront, Application Load Balancer, and API Gateway, allowing it to enforce Web ACLs at the edge or origin.

  • ✓

    AWS Shield Advanced

    Why this is correct

    AWS Shield Advanced is a managed DDoS protection service that provides always-on, enhanced detection and network-layer mitigation beyond the automatic protections of Shield Standard. It grants access to the 24/7 AWS DDoS Response Team, includes AWS WAF at no additional cost, and offers cost protection against scaling charges incurred during an attack. This service is designed to stop large volumetric and state-exhaustion attacks while giving you visibility through metrics and real-time attack diagnostics.

  • ✓

    Amazon CloudFront

    Why this is correct

    Amazon CloudFront is a global content delivery network that caches static and dynamic content at hundreds of edge locations, drastically reducing the load on the origin server. When a DDoS attack is launched, the edge network absorbs and dissipates traffic across many points of presence, preventing any single origin from being overwhelmed. CloudFront also supports security features like origin access control, AWS WAF association, and integration with Shield Advanced, making it a foundational component of a defense-in-depth DDoS strategy.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a continuous threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events using machine learning and threat intelligence to identify suspicious behavior such as port scanning, crypto mining, or credential theft. It generates security findings but operates out-of-band, meaning it does not process or filter actual traffic and cannot block malicious packets or HTTP requests in real time. Therefore, GuardDuty is excellent for detecting signals related to an attack, but it offers no direct DDoS mitigation or absorption capability.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.