Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is using AWS WAF to protect a web application behind an Application Load Balancer. The Security Engineer wants to block requests that contain SQL injection attacks. Which action should the Engineer take?

⚠ Common exam trap

Candidates often confuse AWS Shield Advanced (a DDoS service) with WAF (a web application firewall), or assume that network-layer controls like security groups can inspect application-layer payloads, when in fact only WAF can perform content inspection for SQL injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a WAF rule with a SQL injection match condition and set the action to block.

AWS WAF is the native service for filtering web traffic to Application Load Balancers, and it includes a managed rule set specifically for SQL injection (SQLi) detection. By creating a custom WAF rule with a SQL injection match condition and setting the action to 'Block', the Engineer directly instructs WAF to inspect incoming requests for SQLi patterns and drop matching traffic before it reaches the ALB. This is the correct, service-native approach for blocking SQL injection attacks at the application layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS Shield Advanced to automatically block SQL injection attacks.

    Why it's wrong here

    AWS Shield Advanced is a managed DDoS protection service that mitigates large volumetric attacks (Layer 3/4) and certain Layer 7 events like HTTP floods or TCP SYN floods. It does not perform deep packet inspection on HTTP payloads to detect SQL signatures, so it cannot 'auto-block' SQL injection attempts on its own. While Shield Advanced can integrate with AWS WAF for advanced rate-based rules, you still need explicit WAF SQL injection match rules to block that application-layer attack vector.

  • ✓

    Create a WAF rule with a SQL injection match condition and set the action to block.

    Why this is correct

    AWS WAF's SQL injection match condition inspects HTTP request components—such as the URI, query string, body, cookies, and headers—for known malicious SQL patterns using transformations like URL decode and lowercasing to evade bypass attempts. Setting the rule action to Block causes the AWS WAF web ACL to terminate matching requests before they reach the protected resource, which is exactly the correct mechanism for preventing SQL injection attacks at the application layer.

  • ✗

    Use Amazon GuardDuty to detect and block SQL injection attempts.

    Why it's wrong here

    Amazon GuardDuty is a continuous security monitoring service that analyzes VPC Flow Logs, AWS CloudTrail management events, and DNS logs to identify threat indicators like compromised EC2 instances, cryptocurrency mining, or anomalous API calls. It does not sit inline in the HTTP request path, and it cannot inspect web request content—such as the body of a POST request containing SQL payloads—so it cannot block SQL injection attempts in real time. GuardDuty may generate findings about a potential compromise after the fact, but it is not a web application firewall control.

  • ✗

    Configure the security group of the EC2 instances to block traffic containing SQL injection patterns.

    Why it's wrong here

    Security groups act as a virtual firewall for EC2 instances, filtering traffic based solely on IP addresses, ports, and protocols (Layer 3 and Layer 4). They do not perform deep packet inspection or inspect HTTP request bodies, headers, or query parameters, so they cannot identify or block SQL injection patterns embedded in web traffic. Additionally, security groups are stateful and evaluated per-interface, but regardless of configuration, they lack the application-layer awareness required to mitigate this threat.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.