Courseiva

SAA-C03 Design Secure Architectures Practice Question

A company's public-facing application is experiencing a Distributed Denial of Service (DDoS) attack. The application is hosted on EC2 instances behind an Application Load Balancer (ALB). Which TWO AWS services or features can be used to mitigate this attack and protect the application?

⚠ Common exam trap

Candidates often confuse AWS Shield Standard with Advanced, or assume Security Groups can block DDoS attacks. Security Groups are stateful firewalls for instance-level traffic, not a solution for large-scale distributed volumetric DDoS mitigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Shield Advanced for enhanced DDoS detection and mitigation.

Protecting against DDoS attacks requires a multi-layered approach. AWS Shield provides automatic protection for all AWS customers, while Shield Advanced offers enhanced detection and mitigation for sophisticated attacks. AWS WAF complements this by allowing administrators to create rules that block malicious traffic patterns, such as SQL injection or high-volume IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Shield Advanced for enhanced DDoS detection and mitigation.

    Why this is correct

    AWS Shield Advanced provides additional protections for resources like ALBs and CloudFront distributions. It offers 24/7 access to the AWS Shield Response Team (SRT) and provides more sophisticated detection mechanisms to identify and mitigate large-scale or complex DDoS attacks that target the application layer.

  • ✓

    AWS WAF with rate-based rules to block IP addresses with high request volumes.

    Why this is correct

    AWS WAF allows for the creation of rate-based rules that monitor the number of requests coming from a single IP address. If the threshold is exceeded, WAF can automatically block that IP for a period, which is highly effective against certain types of application-layer DDoS attacks.

  • ✗

    Amazon GuardDuty to identify and block malicious traffic at the VPC level.

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior within your AWS accounts. While it can identify that an attack is occurring, it is a detective service rather than a real-time mitigation tool designed to block high-volume DDoS traffic at the edge.

  • ✗

    Amazon Inspector to scan EC2 instances for vulnerabilities during the attack.

    Why it's wrong here

    Amazon Inspector is an automated vulnerability management service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure. It is a proactive security tool used for assessment, but it does not provide active protection or mitigation capabilities against an ongoing DDoS attack.

  • ✗

    AWS PrivateLink to hide the application from the public internet.

    Why it's wrong here

    AWS PrivateLink provides private connectivity between VPCs, AWS services, and on-premises networks without exposing traffic to the public internet. While it improves privacy, it is not a solution for a public-facing application that must remain accessible to general users over the internet during a DDoS attack.

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 149 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.