Courseiva
Security and Compliance →hardMultiple Select

DOP-C02 Security and Compliance Practice Question

Which THREE services can be used to protect a VPC from malicious traffic? (Choose 3.)

⚠ Common exam trap

Test-takers frequently confuse AWS Shield (a DDoS protection service) with a VPC-level firewall, not realizing it operates at the edge/global layer and does not filter traffic within the VPC itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network ACLs

Network ACLs (NACLs) are stateless, subnet-level firewalls that filter traffic based on rules evaluating source/destination IP, protocol, and port. They provide an additional layer of defense by explicitly allowing or denying inbound and outbound traffic at the subnet boundary, making them a correct choice for protecting a VPC from malicious traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Network ACLs

    Why this is correct

    Network ACLs are a stateless firewall layer operating at the subnet boundary, inspecting traffic entering and leaving each subnet. Rules are evaluated in numeric order, and because they are stateless, you must explicitly allow both inbound and outbound traffic, including return traffic. By default, a custom Network ACL denies all traffic until you add allow rules, while the default NACL permits all traffic. This makes NACLs ideal for subnet-level deny lists and for enforcing broad boundaries, but they lack the stateful awareness of security groups.

  • ✓

    Security Groups

    Why this is correct

    Security groups act as a stateful virtual firewall at the instance or elastic network interface (ENI) level, filtering traffic based on allow rules only. They automatically allow return traffic for established connections, so you do not need separate outbound rules for responses. Security groups support both allow and deny via their implicit default-deny behavior, but they do not evaluate rules in priority order; all rules are considered. They are the first line of defense for individual resources, but they cannot perform inline stateless filtering or block traffic at the subnet boundary.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield is a managed Distributed Denial of Service (DDoS) protection service, not a general-purpose traffic filter for your VPC. Shield Standard is enabled automatically, while Shield Advanced provides enhanced detection and mitigation for volumetric and state-exhaustion attacks. It does not replace Network ACLs, Security Groups, or Network Firewall because it does not inspect application-layer traffic or enforce allow/deny policies. Shield is designed to keep your resources available during DDoS attacks, not to protect against unauthorized access or malicious payloads.

  • ✗

    Amazon Route 53 Resolver

    Why it's wrong here

    Amazon Route 53 Resolver is a DNS resolution service that translates domain names into IP addresses for resources within your VPC and on-premises networks. It provides recursive and conditional forwarding rules, but it does not evaluate or filter network traffic at the packet level. While DNS-based threat filtering can be layered on top of Route 53 Resolver (e.g., via Route 53 Resolver DNS Firewall), the resolver itself offers no VPC traffic protection. It is a control-plane service for name resolution, not a data-plane security control.

  • ✓

    AWS Network Firewall

    Why this is correct

    AWS Network Firewall is a managed stateful firewall service that inspects all traffic at the VPC level, providing deep packet inspection, intrusion prevention, and domain filtering. It can be deployed across multiple Availability Zones and centrally managed, complementing Security Groups and Network ACLs. Unlike NACLs and SGs, Network Firewall supports advanced rules like Suricata-compatible rules and allows you to block malicious traffic based on signatures or threat intelligence. This makes it the appropriate choice for organizations needing strong, centralized traffic inspection and filtering beyond basic subnet or instance-level controls.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.