SAP-C02 Design for New Solutions Practice Question
A company is building a new web application that will be accessed by users globally. They want to minimize latency and protect against DDoS attacks. Which AWS service should they use as the entry point?
⚠ Common exam trap
Many exam-takers confuse AWS Global Accelerator with CloudFront because both improve latency globally, but Global Accelerator does not cache content or provide application-layer DDoS protection, making it unsuitable as the primary entry point for a web application requiring both features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudFront
Amazon CloudFront is correct because it is a global content delivery network (CDN) that caches content at edge locations close to users, reducing latency for static and dynamic content. It also provides built-in DDoS protection through AWS Shield Standard and can integrate with AWS WAF for additional layer 7 filtering, making it the ideal entry point for a globally accessed web application requiring both low latency and DDoS mitigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Elastic Load Balancing
Why it's wrong here
Elastic Load Balancing distributes traffic across targets within a Region; it provides no global anycast routing or edge absorption of volumetric DDoS. It is tempting because it fronts web applications, but that suits regional traffic distribution, not global entry, where Amazon CloudFront with AWS Shield fits.
- ✗
AWS Global Accelerator
Why it's wrong here
Global Accelerator improves performance by routing traffic over the AWS network but does not cache content or provide the same DDoS protection as CloudFront.
- ✓
Amazon CloudFront
Why this is correct
Amazon CloudFront terminates TLS at edge locations and caches content close to global users, directly reducing latency. Its integration with AWS Shield Standard provides automatic DDoS protection at no extra cost, satisfying both the latency and DDoS constraints named in the stem.
- ✗
Amazon Route 53
Why it's wrong here
Amazon Route 53 resolves DNS names to endpoints; it does not proxy traffic, cache content at edge locations, or absorb DDoS at the network edge. It is tempting because it offers latency-based routing, but that suits DNS resolution, not traffic entry, where Amazon CloudFront with AWS Shield fits.
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.