SCS-C02 AWS WAF Practice Question
A startup is building a web application on AWS. They have an Application Load Balancer (ALB) in front of EC2 instances in an Auto Scaling group. They want to protect the application from common web exploits like SQL injection and cross-site scripting. They also need to allow only traffic from certain geographic regions. Which AWS service should they use to achieve these requirements?
⚠ Common exam trap
SCS-C02 often tests the distinction between WAF and Shield, and candidates might think Shield Advanced provides WAF capabilities, but it's primarily for DDoS; also, they might confuse security groups with WAF for application-layer protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF
AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting. It also allows you to create geo-match conditions to allow or block traffic based on geographic regions, meeting both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS WAF
Why this is correct
AWS WAF is the correct service because it operates at Layer 7 and can inspect every HTTP(S) request forwarded to the ALB, allowing you to block SQL injection, cross-site scripting, and other application-layer attacks via managed or custom rules. It also supports geo-match and rate-based rules, which are essential for a web-facing application. By associating a WAF web ACL directly with the ALB, traffic is filtered before reaching the application, giving you granular control over the actual request content.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced is designed to protect against distributed denial-of-service attacks at the network and transport layers (and some volumetric Layer 7 floods), but it does not inspect HTTP request bodies or headers for SQL injection, XSS, or geo-specific filters. Shield Advanced provides enhanced DDoS detection, cost protection, and access to the AWS DDoS Response Team, but it does not perform application-layer content filtering. Therefore, it cannot replace AWS WAF for blocking OWASP-style application attacks.
- ✗
Security groups on the ALB
Why it's wrong here
Security groups attached to the ALB are stateful virtual firewalls that filter traffic based on source IP, destination IP, port, and protocol — Layer 3/4 characteristics. They do not parse the HTTP request line, headers, or body, so they cannot identify malicious payloads like SQLi or XSS. Statefulness simply means return traffic is automatically allowed; it has no bearing on application-layer inspection and cannot act on the content of the request.
- ✗
Network ACLs on the ALB subnets
Why it's wrong here
Network ACLs on the ALB subnets are stateless, subnet-level access control lists that evaluate only IP addresses, ports, and protocols at Layer 3/4, with no visibility into the application payload. Because they are stateless, both inbound and outbound rules must be explicitly configured for return traffic. NACLs are completely unaware of HTTP semantics and cannot apply geo-match or content-based filtering rules, making them unsuitable for blocking SQL injection or XSS.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.