Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to protect its Amazon EC2 instances from distributed denial-of-service (DDoS) attacks at the network layer. Which AWS service should be used?

⚠ Common exam trap

Watch out — candidates often confuse AWS WAF (Layer 7) with network-layer DDoS protection, or assume Amazon CloudFront's edge caching alone is sufficient for all DDoS types, but Shield Advanced is the specific service designed for comprehensive network-layer (Layer 3/4) DDoS mitigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Shield Advanced

AWS Shield Advanced provides enhanced protections for Amazon EC2 instances against network-layer (Layer 3/4) DDoS attacks, such as SYN floods, UDP reflection attacks, and other volumetric attacks. It includes always-on traffic monitoring, automated mitigation, and access to the DDoS Response Team (DRT) for custom mitigations, making it the correct choice for network-layer DDoS protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudFront

    Why it's wrong here

    Amazon CloudFront distributes content over a global network of edge POPs, and its anycast routing and edge caching can absorb some volumetric attacks so they never reach the origin EC2 instances. However, CloudFront only protects traffic that is served through a distribution, and it does not provide the dedicated always-on monitoring, mitigation tuning, or cost protections of AWS Shield Advanced. Since the company's EC2 instances are the target and may not even be fronted by CloudFront, CloudFront alone isn't the right protection service.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, Route 53 DNS logs, and CloudTrail event history to identify anomalous behavior such as reconnaissance or port scanning. It does not sit in the network path and cannot drop or scrub malicious traffic, so it has no direct ability to mitigate a DDoS attack. GuardDuty findings can trigger automated corrective actions, but the service itself is detective and doesn't prevent or stop an ongoing DDoS flood.

  • ✓

    AWS Shield Advanced

    Why this is correct

    AWS Shield Advanced is purpose-built for DDoS protection, providing enhanced always-on detection and automatic inline mitigation for network-layer (L3/L4) attacks such as SYN floods and UDP reflection. It works by absorbing attack traffic and rerouting it to AWS's global scrubbing infrastructure while maintaining availability of protected resources like EC2 instances. Advanced also adds cost protection (DDoS-induced spikes are charged back as credits), access to the AWS DDoS Response Team (DRT), and integration with AWS WAF for additional Layer 7 defense. This is the service designed to directly protect EC2 from DDoS attacks.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF operates at the application layer (Layer 7) and filters incoming HTTP(S) requests using customizable rules, such as IP match conditions, rate-based blocking, SQL injection, and cross-site scripting protections. While a rate-based rule can mitigate certain HTTP flood attacks, WAF cannot defend against network-layer DDoS events like TCP SYN floods or UDP amplification attacks because those never reach the WAF engine as HTTP requests. The company's requirement is generic DDoS protection, not just web request filtering, so WAF alone is insufficient.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.