Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

Drag and drop the steps to set up AWS Shield Advanced with automatic application layer DDoS mitigation in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Step 1: Subscribe to AWS Shield Advanced. Step 2: Add protection to AWS resources. Step 3: Integrate with AWS WAF and create a mitigation rule. Step 4: Enable health-based detection.

Shield Advanced requires subscription first, then resource protection, WAF integration, mitigation rule, and health-based detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Step 1: Subscribe to AWS Shield Advanced. Step 2: Add protection to AWS resources. Step 3: Integrate with AWS WAF and create a mitigation rule. Step 4: Enable health-based detection.

    Why this is correct

    This is the correct order because you must first subscribe to Shield Advanced to access its features, then specify the resources to protect before configuring WAF rules, then create the mitigation rule, and finally enable health-based detection to enhance automatic mitigation.

  • ✗

    Step 1: Add protection to AWS resources. Step 2: Subscribe to AWS Shield Advanced. Step 3: Integrate with AWS WAF and create a mitigation rule. Step 4: Enable health-based detection.

    Why it's wrong here

    This sequence is invalid because Shield Advanced is an opt-in, paid AWS service that must be subscribed to before the Add protection API will accept any resource. If you attempt to protect a resource first, the console/API has no active subscription context and returns an error, meaning the remaining configuration steps cannot be performed. Subscription is the prerequisite that enables all subsequent Shield Advanced capabilities.

  • ✗

    Step 1: Subscribe to AWS Shield Advanced. Step 2: Integrate with AWS WAF and create a mitigation rule. Step 3: Add protection to AWS resources. Step 4: Enable health-based detection.

    Why it's wrong here

    This ordering is flawed because the WAF mitigation rule is created to act on the specific resources you want Shield Advanced to protect, but no protections have been added yet. The rule's name, scope, and association depend on the ARN of the protected resource; without a protected resource, the rule cannot be attached or deployed. Adding protection first ensures the rule has a concrete target when it is integrated.

  • ✗

    Step 1: Subscribe to AWS Shield Advanced. Step 2: Add protection to AWS resources. Step 3: Enable health-based detection. Step 4: Integrate with AWS WAF and create a mitigation rule.

    Why it's wrong here

    Health-based detection is an advanced mitigation enhancement that should only be enabled after the WAF mitigation rule exists, because it uses health-check data to decide when to activate that rule. If you enable it before the rule is created, the health checks have no mitigation policy to trigger, so the detection is inert. Thus the WAF integration step must precede the health-based detection step in the setup.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.