SCS-C02 Infrastructure Security Practice Question
A company wants to use AWS WAF to protect its web application from common web exploits. Which AWS service must be integrated with AWS WAF to provide this protection?
⚠ Common exam trap
Test-takers frequently confuse network-layer controls (Security Groups, NACLs) with application-layer protection, assuming any firewall can be used with WAF, but only ALB and CloudFront provide the necessary Layer 7 integration for AWS WAF.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application Load Balancer or Amazon CloudFront
AWS WAF is a web application firewall that inspects HTTP/HTTPS traffic at Layer 7. It must be integrated with a service that can terminate HTTP/HTTPS connections and forward the traffic to WAF for inspection. Both Application Load Balancer (ALB) and Amazon CloudFront support this integration, allowing WAF to filter requests based on rules such as SQL injection or cross-site scripting. Security Groups and Network ACLs operate at the network and transport layers (Layers 3/4) and cannot provide Layer 7 inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security Groups
Why it's wrong here
Security groups are stateful virtual firewalls that filter traffic at the network interface (ENI) level based on IP addresses, protocols, and ports. AWS WAF cannot be integrated with or attached to a security group because security groups have no visibility into HTTP request content such as URI paths, headers, or body payloads. They block or allow connections, but they do not inspect application-layer traffic for SQL injection, XSS, or bot signatures, which is why they cannot replace or host WAF protections.
- ✓
Application Load Balancer or Amazon CloudFront
Why this is correct
AWS WAF is a managed Layer 7 web application firewall that you attach by associating a web access control list (ACL) with a supported resource, specifically an Application Load Balancer for regional HTTP/S requests or Amazon CloudFront for edge-based delivery. An ALB terminates HTTP/HTTPS and forwards requests to targets, giving WAF a point to inspect URI, headers, and body; CloudFront provides the same inspection at CloudFront edge locations before origin processing. This is the supported integration path, along with API Gateway and App Runner, so the correct target is an ALB or CloudFront.
- ✗
Amazon Route 53
Why it's wrong here
Amazon Route 53 is an authoritative DNS service and it never terminates HTTP/HTTPS connections or views the application-layer payload of a web request. Since AWS WAF must inspect actual HTTP traffic as it is proxied through a resource, Route 53 only answers DNS queries that resolve a domain name to an IP address. It has no reverse-proxy or origin role, so associating WAF with Route 53 is not supported.
- ✗
Network ACLs
Why it's wrong here
Network ACLs are stateless access control lists applied at the VPC subnet boundary, filtering traffic by IP address, port, and protocol at Layers 3 and 4 of the OSI model. They operate on connection state metadata and cannot understand HTTP methods, paths, cookies, or body content, which are required for WAF rules. NACLs do not integrate with AWS WAF and, unlike security groups, they are not even tied to instance security; they are purely network-layer filters.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.