SAP-C02 Design for New Solutions Practice Question
A company is designing a new web application that will run on Amazon EC2 instances behind an Application Load Balancer. The application must handle millions of requests per day. To reduce latency and offload traffic from the EC2 instances, which AWS service should be placed in front of the load balancer?
⚠ Common exam trap
SAP-C02 often tests the confusion between CloudFront (caching CDN that offloads origin) and Global Accelerator (network path optimization without caching) — candidates must match 'offload traffic' to CloudFront.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudFront
Amazon CloudFront is a CDN that caches content at edge locations worldwide, reducing latency for end users and offloading a large portion of requests from the origin EC2 instances behind the ALB. Placing CloudFront in front of the ALB is the standard AWS pattern for high-volume web applications needing low latency and origin offload.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon CloudFront
Why this is correct
CloudFront caches content at edge locations worldwide, so repeated requests are served closer to users rather than reaching the load balancer. This reduces latency and offloads origin traffic from the EC2 instances, satisfying the requirement to place a service in front of the ALB.
- ✗
AWS Global Accelerator
Why it's wrong here
AWS Global Accelerator routes traffic over the AWS global network using static anycast IP addresses; it does not cache content, so origin instances still serve every request. It is tempting because it improves latency for global users, and would be correct when the requirement is faster routing rather than reducing origin load.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced provides DDoS protection and cost safeguards, not caching or content delivery, so it cannot offload requests from the EC2 instances. It is tempting because it sits in front of load balancers, and would be the correct choice when the requirement is defending against volumetric or application-layer DDoS attacks.
- ✗
AWS WAF
Why it's wrong here
AWS WAF filters HTTP requests against rules to block exploits and bots; it does not cache responses or serve content, so it cannot reduce latency or offload traffic. It is tempting because it deploys in front of an Application Load Balancer, and would be correct when the requirement is filtering malicious web requests.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.