SCS-C02 Infrastructure Security Practice Question
A security engineer is designing a web application that will run on EC2 instances behind an Application Load Balancer (ALB). The application must be protected from common web exploits like SQL injection and cross-site scripting. Which AWS service should be used to provide this protection?
⚠ Common exam trap
The trap is confusing DDoS protection (Shield) or network-layer filtering (NACLs, Security Groups) with application-layer exploit protection (WAF); only WAF inspects HTTP payloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF
AWS WAF is a Layer 7 web application firewall that inspects HTTP/HTTPS requests and can block common exploits like SQL injection and cross-site scripting using managed rule groups (e.g., AWSManagedRulesCommonRuleSet, SQLiRuleSet, XSSRuleSet). It integrates natively with ALB, CloudFront, and API Gateway, making it the correct choice for protecting an ALB-fronted web app.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS WAF
Why this is correct
AWS WAF integrates directly with the Application Load Balancer, inspecting HTTP requests against rule groups that block SQL injection and cross-site scripting patterns before traffic reaches the EC2 instances. This satisfies the stem's requirement for protection from common web exploits at the ALB layer, filtering malicious payloads inline.
- ✗
Network ACLs
Why it's wrong here
Network ACLs operate at the subnet level as a stateless packet filter, inspecting only IP addresses, ports, and protocols; they lack the application-layer inspection required to detect and block SQL injection or cross-site scripting payloads embedded in HTTP requests. This option is tempting because network ACLs are a standard perimeter defence for controlling traffic to subnets, and they would be the correct choice if the requirement were to restrict inbound IP ranges or block specific ports at the network boundary rather than to filter application-layer attacks.
- ✗
Security Groups
Why it's wrong here
Security groups filter traffic by IP, port and protocol at the instance level, so they cannot inspect HTTP request payloads for SQL injection or cross-site scripting patterns. They are the right control for restricting network reachability, such as allowing only the ALB to reach backend instances.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced mitigates volumetric DDoS attacks at layers 3 and 4, not application-layer injection or scripting payloads. It is the correct choice when the requirement is DDoS resilience with cost protection, rather than inspecting HTTP requests for exploits.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.