SAP-C02 Design for New Solutions Practice Question
A company is designing a new application that requires a global content delivery network with low latency and DDoS protection. Which combination of AWS services should be used?
⚠ Common exam trap
Many exam-takers confuse AWS Global Accelerator with a CDN, but Global Accelerator does not cache content—it only optimizes network routing, making it unsuitable for content delivery without CloudFront.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudFront and AWS Shield
Amazon CloudFront provides a global content delivery network (CDN) with low latency by caching content at edge locations worldwide. AWS Shield, specifically Shield Advanced, offers managed DDoS protection against large-scale attacks, including layer 3/4 and layer 7 threats. Together, they meet the requirement for both low-latency content delivery and DDoS mitigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon CloudFront and AWS Shield
Why this is correct
Amazon CloudFront caches content at edge locations worldwide, cutting latency for global users, while AWS Shield provides managed DDoS protection at layers 3, 4 and 7. Together they satisfy the stem's dual requirement: a global content delivery network with low latency and integrated DDoS mitigation.
- ✗
AWS Global Accelerator and Amazon CloudFront
Why it's wrong here
AWS Global Accelerator routes traffic over the AWS backbone to regional endpoints; it does not cache content at edge locations, so it fails the content delivery requirement. It is tempting because Global Accelerator improves latency and absorbs DDoS, and would suit TCP/UDP acceleration for non-cacheable workloads.
- ✗
Amazon Route 53 and AWS Shield
Why it's wrong here
Amazon Route 53 provides DNS resolution and AWS Shield adds DDoS protection, but neither caches content at edge locations, so no CDN is delivered. It is tempting because both are commonly paired for resilient global DNS, and would suit directing users to healthy endpoints rather than caching content.
- ✗
AWS WAF and Amazon CloudFront
Why it's wrong here
AWS WAF filters HTTP requests against web exploits, and CloudFront caches content, but WAF alone does not provide the volumetric DDoS absorption the scenario requires. It is tempting because WAF integrates with CloudFront, and would suit blocking SQL injection or bot traffic on a web application.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.