SCS-C02 Infrastructure Security Practice Question
A company is deploying a multi-tier web application on AWS. The application uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances in private subnets. The security team wants to protect the application from common web exploits like SQL injection and cross-site scripting. Which AWS service should be used?
⚠ Common exam trap
Many candidates confuse AWS Network Firewall (Layer 3/4 filtering) with a web application firewall, not realizing that SQL injection and XSS require Layer 7 HTTP payload inspection, which only AWS WAF provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF.
AWS WAF is a web application firewall that helps protect web applications from common web exploits such as SQL injection and cross-site scripting (XSS). It integrates directly with an Application Load Balancer (ALB) to inspect HTTP/HTTPS requests and filter malicious traffic based on customizable rules, including managed rule groups for OWASP Top 10 threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS WAF.
Why this is correct
AWS WAF is a Layer 7 web application firewall that inspects HTTP/HTTPS requests before they reach the web tier. It runs managed rule groups, including AWS Managed Rules for SQL injection and cross-site scripting, and can be deployed on an Application Load Balancer, Amazon CloudFront, or Amazon API Gateway. Because it can parse the request body and headers, it can block malicious signatures while letting legitimate traffic through.
- ✗
AWS Network Firewall.
Why it's wrong here
AWS Network Firewall is a managed firewall that provides stateful inspection at the VPC network boundary, filtering by IP addresses, ports, and protocols, and supports Suricata rules for basic intrusion prevention. However, it does not terminate TLS or fully decode application-layer payloads, so it cannot reliably identify SQL injection or XSS patterns in web requests. It is designed for network-level segmentation and egress control, not for application-layer attack mitigation, so it would not block the specific web attacks described.
- ✗
AWS Shield Advanced.
Why it's wrong here
AWS Shield Advanced is a DDoS protection service that defends against infrastructure-layer attacks such as SYN floods, UDP reflection, and volumetric traffic that target availability. It operates primarily at layers 3 and 4 and, while it can include AWS WAF for application-layer DDoS protections, Shield itself does not inspect HTTP bodies for SQL injection or XSS. A web application exploit is a focused application vulnerability attempt, not a resource-exhaustion attack, and Shield would not stop it.
- ✗
AWS Security Hub.
Why it's wrong here
AWS Security Hub is a cloud security posture management service that consolidates findings from GuardDuty, Inspector, Config, Macie, and other AWS tools into a single dashboard, and it applies security standards like CIS Foundations. It is an out-of-band aggregator and does not sit in the data path, so it cannot enforce allow/deny decisions or filter incoming traffic. Even if it detects a vulnerability, remediation requires a separate service like AWS WAF; Security Hub itself cannot protect a web application in real time.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.