SAP-C02 AWS Shield Advanced Practice Question
A financial services company runs a critical application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application is deployed across multiple Availability Zones. The company recently experienced a DDoS attack that overwhelmed the ALB and caused downtime. The security team wants to implement a solution that can absorb DDoS attacks at the edge and only forward legitimate traffic to the ALB. Additionally, the company needs to protect sensitive data in transit using TLS 1.3. What should the solutions architect do?
⚠ Common exam trap
SAP-C02 often tests the misconception that AWS WAF or Shield Standard alone can absorb large-scale DDoS attacks, but only CloudFront with Shield Advanced provides edge absorption and advanced mitigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy Amazon CloudFront in front of the ALB with AWS Shield Advanced and enforce TLS 1.3.
Amazon CloudFront is a global content delivery network that caches content at edge locations, absorbing volumetric DDoS attacks before they reach the origin ALB. AWS Shield Advanced provides enhanced DDoS protection with 24/7 access to the AWS DDoS Response Team (DRT) and cost protection, and CloudFront supports TLS 1.3 for encryption in transit. Together, they meet the requirements of edge absorption and TLS 1.3 enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy Amazon CloudFront in front of the ALB with AWS Shield Advanced and enforce TLS 1.3.
Why this is correct
CloudFront absorbs volumetric DDoS at edge locations, forwarding only legitimate traffic to the ALB, satisfying the edge-absorption constraint. Shield Advanced adds enhanced mitigation and cost protection. CloudFront supports TLS 1.3 via security policies, meeting the in-transit encryption requirement. ALB alone cannot absorb edge-level attacks.
- ✗
Use AWS WAF with rate-based rules and associate it with the ALB.
Why it's wrong here
AWS WAF rate-based rules throttle request volume per source IP at the ALB, but the ALB still terminates the flood, so attack traffic reaches the origin and TLS 1.3 termination is not provided. It is tempting because WAF filters application-layer exploits, which suits blocking SQL injection or bad bots rather than volumetric absorption at the edge.
- ✗
Use an AWS Network Firewall and configure stateful rules to block malicious IPs.
Why it's wrong here
Network Firewall inspects traffic entering a VPC, sitting behind the ALB rather than at the edge, so it cannot absorb a volumetric flood before it reaches the load balancer, and it does not terminate TLS 1.3 for clients. It is tempting because stateful rules block malicious IPs, which suits east-west or egress filtering inside a VPC.
- ✗
Enable AWS Shield Standard and use security groups to restrict traffic.
Why it's wrong here
Shield Standard is automatically enabled and only mitigates common layer 3/4 attacks; security groups filter instance traffic after the ALB, so they cannot absorb a flood at the edge or terminate TLS 1.3. It is tempting because Shield Standard is free and always on, which suits basic protection when no edge absorption or TLS requirement exists.
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.