Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is using AWS Shield Advanced to protect its web application against DDoS attacks. Which additional AWS service can be used to automatically mitigate application layer attacks?

⚠ Common exam trap

Test-takers frequently confuse AWS WAF with AWS Network Firewall or Firewall Manager, mistakenly believing that any firewall service can handle application-layer attacks, but only AWS WAF provides Layer 7 inspection and mitigation for HTTP/HTTPS traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF

AWS WAF is the correct choice because it integrates directly with AWS Shield Advanced to provide application-layer (Layer 7) DDoS mitigation. Shield Advanced handles network and transport layer attacks, while AWS WAF uses web access control lists (ACLs) to inspect HTTP/HTTPS traffic and block malicious requests such as SQL injection or cross-site scripting, which are common application-layer attack vectors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Network Firewall

    Why it's wrong here

    AWS Network Firewall is a managed stateful firewall that inspects traffic at the network and transport layers (IP, ports, protocols) across a VPC. It lacks the ability to parse HTTP/HTTPS application headers or URI patterns, so it cannot distinguish benign web traffic from layer 7 DDoS flood. While it can enforce network ACL-like rules, it does not provide the application-layer visibility required for mitigating attacks targeting web applications.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a continuous security monitoring service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events to identify suspicious behavior using machine learning and threat intelligence. It functions as a detection mechanism, alerting on anomalies like port scans or compromised instances, but it does not sit inline to filter or absorb malicious traffic. As a result, it cannot actively block or reduce DDoS attack volume.

  • ✗

    AWS Firewall Manager

    Why it's wrong here

    AWS Firewall Manager is a central policy management service that lets you centrally configure and govern AWS WAF rules, Shield Advanced protections, and security groups across accounts in an organization. It automates the deployment and enforcement of security policies, but it does not directly process or inspect live traffic. Therefore, while it could help deploy WAF rules, it is not itself the service that mitigates application-layer DDoS attacks.

  • ✓

    AWS WAF

    Why this is correct

    AWS WAF is a web application firewall that monitors and filters HTTP(S) requests based on conditions like IP reputation, country, URI, and SQL injection signatures. When integrated with AWS Shield Advanced, it provides the primary mechanism for application layer (L7) DDoS mitigation—enabling you to add rate-based rules and block anomalous traffic before it reaches the origin. This direct, request-level inspection makes it the correct option for protecting a web application.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.