Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company runs a critical application on EC2 instances behind an Application Load Balancer. The security team suspects that a DDoS attack is targeting the application. Which AWS service can be used to absorb and mitigate the attack at the network layer before traffic reaches the ALB?

⚠ Common exam trap

Many candidates confuse AWS WAF (Layer 7) with network-layer protection, or assume that Network ACLs can handle DDoS attacks, but only AWS Shield Advanced provides dedicated, scalable mitigation for Layer 3/4 attacks at the network perimeter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Shield Advanced

AWS Shield Advanced provides enhanced protections against larger and more sophisticated DDoS attacks, including network-layer (Layer 3/4) attacks such as UDP floods, SYN floods, and reflection attacks. It integrates directly with Application Load Balancers to absorb and mitigate malicious traffic before it reaches the ALB, ensuring the application remains available. This makes it the correct choice for mitigating a DDoS attack at the network layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF is a web application firewall that operates at Layer 7, inspecting HTTP/S requests for signatures, SQL injection, cross-site scripting, and rate-based rules. It has no visibility into or control over network- and transport-layer traffic such as SYN floods, UDP reflection attacks, or ICMP floods, which target the EC2 instance's network stack. Additionally, WAF is attached to resources like CloudFront, Application Load Balancers, or API Gateway, not directly to EC2 instances, so it cannot protect the instance itself from a network-layer DDoS.

  • ✗

    AWS Identity and Access Management (IAM)

    Why it's wrong here

    AWS Identity and Access Management (IAM) is a control-plane service that authenticates principals and authorizes API calls by evaluating policies before any request reaches the network data plane. IAM cannot inspect, filter, or reroute inbound packets destined for an EC2 instance, and it provides no traffic congestion controls or mitigation capacity. A DDoS attack overwhelms the network interface and kernel stack, whereas IAM only determines whether an API request is allowed, making it completely unrelated to availability against floods.

  • ✗

    Network ACLs

    Why it's wrong here

    Network ACLs are stateless packet filters applied at the subnet boundary that allow or deny traffic based on five-tuple rules encompassing source/destination IP, port, and protocol. While they can manually block traffic from known attacking IPs, they cannot detect distributed attack patterns, absorb volumetric floods, or scale mitigation resources in response to shifting attack vectors. Because NACLs are stateless, every inbound and outbound flow must be governed by explicit rules, which adds operational risk and makes them an ineffective standalone defense against DDoS.

  • ✓

    AWS Shield Advanced

    Why this is correct

    AWS Shield Advanced is the purpose-built DDoS mitigation service that protects at the network and transport layers (Layers 3 and 4), covering SYN floods, UDP reflection attacks, and other high-volume floods against EC2 instances and associated Elastic IPs. It provides always-on detection, automatic inline mitigation, and access to the AWS DDoS Response Team (DRT) for rapid manual intervention in complex attacks. For a critical EC2 application, Shield Advanced is the correct choice because it is designed to maintain availability when incoming attack traffic saturates the network path, and it offers cost protection against scaling charges triggered by attacks.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.