Courseiva
Design for New Solutions →mediumMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A company is designing a new application that requires a global content delivery network with low latency and DDoS protection. Which combination of AWS services should be used?

⚠ Common exam trap

Many exam-takers confuse AWS Global Accelerator with a CDN, but Global Accelerator does not cache content—it only optimizes network routing, making it unsuitable for content delivery without CloudFront.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudFront and AWS Shield

Amazon CloudFront provides a global content delivery network (CDN) with low latency by caching content at edge locations worldwide. AWS Shield, specifically Shield Advanced, offers managed DDoS protection against large-scale attacks, including layer 3/4 and layer 7 threats. Together, they meet the requirement for both low-latency content delivery and DDoS mitigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon CloudFront and AWS Shield

    Why this is correct

    Amazon CloudFront caches content at edge locations worldwide, cutting latency for global users, while AWS Shield provides managed DDoS protection at layers 3, 4 and 7. Together they satisfy the stem's dual requirement: a global content delivery network with low latency and integrated DDoS mitigation.

  • ✗

    AWS Global Accelerator and Amazon CloudFront

    Why it's wrong here

    AWS Global Accelerator routes traffic over the AWS backbone to regional endpoints; it does not cache content at edge locations, so it fails the content delivery requirement. It is tempting because Global Accelerator improves latency and absorbs DDoS, and would suit TCP/UDP acceleration for non-cacheable workloads.

  • ✗

    Amazon Route 53 and AWS Shield

    Why it's wrong here

    Amazon Route 53 provides DNS resolution and AWS Shield adds DDoS protection, but neither caches content at edge locations, so no CDN is delivered. It is tempting because both are commonly paired for resilient global DNS, and would suit directing users to healthy endpoints rather than caching content.

  • ✗

    AWS WAF and Amazon CloudFront

    Why it's wrong here

    AWS WAF filters HTTP requests against web exploits, and CloudFront caches content, but WAF alone does not provide the volumetric DDoS absorption the scenario requires. It is tempting because WAF integrates with CloudFront, and would suit blocking SQL injection or bot traffic on a web application.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.