Drag a concept onto its matching description — or click a concept then click the description.
Web application firewall
DDoS protection
Key management and encryption
Identity and access management
Data discovery and classification
Match each AWS service to its primary security function.
Drag a concept onto its matching description — or click a concept then click the description.
Web application firewall
DDoS protection
Key management and encryption
Identity and access management
Data discovery and classification
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
AWS WAF: Web application firewall that protects against common web exploits.
These are core AWS security services with distinct purposes.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
AWS WAF: Web application firewall that protects against common web exploits.
Why this is correct
AWS WAF is a web application firewall that operates at Layer 7 (HTTP/S) to inspect and filter traffic destined for Amazon CloudFront, an Application Load Balancer, or Amazon API Gateway. It uses managed or custom rules to block common web exploits such as SQL injection (SQLi), cross-site scripting (XSS), excessive URI lengths, and geo-based attacks. Because it sees application-layer requests and can apply rate-based rules, it is purpose-built for web application protection, not network or transport-level attack mitigation.
AWS Shield: Managed DDoS protection service.
Why this is correct
AWS Shield is a fully managed DDoS protection service; the always-on AWS Shield Standard is automatically enabled for all AWS customers at no cost, absorbing common network and transport-layer DDoS attacks. AWS Shield Advanced adds enhanced detection, near real-time visibility via CloudWatch metrics, and 24/7 access to the DDoS Response Team, along with cost protection against scaling-related charges. It defends against volumetric and protocol-level attacks such as SYN floods and UDP reflection attacks, making it distinct from a web application firewall.
Amazon GuardDuty: Threat detection service that monitors for malicious activity.
Why this is correct
Amazon GuardDuty is a continuous threat detection service that consumes foundational data sources, including AWS CloudTrail management events, VPC Flow Logs, and DNS query logs. Using machine learning, anomaly detection, and curated threat intelligence feeds, it raises findings for suspicious activities like compromised credentials, cryptocurrency mining, or unusual API behavior. Unlike WAF and Shield, GuardDuty is not designed to stop attacks in real time; instead, it detects indicators of compromise so customers can investigate and remediate.
AWS KMS: Managed service for creating and controlling encryption keys.
Why this is correct
AWS Key Management Service (KMS) is a regional, managed service used to create, store, rotate, and control the life cycle of customer master keys and, more recently, KMS keys. These keys are protected by FIPS 140-2 validated hardware security modules (HSMs) and can be used for envelope encryption, where a KMS key encrypts data keys that then encrypt customer data in services such as S3, EBS, and RDS. Access is governed by IAM and key policies, with auditability through CloudTrail, so it is fundamentally about cryptographic control, not attack filtering or DDoS defense.
AWS WAF: Managed DDoS protection service.
Why it's wrong here
This pairing is incorrect: AWS WAF is not a managed DDoS protection service; that role belongs to AWS Shield. DDoS protection mitigates volumetric, protocol, and other attacks that target network availability, often at Layers 3 and 4, whereas WAF operates at Layer 7 and blocks specific HTTP/S request patterns. While using AWS WAF can help stop the application-layer flood component of an attack, it cannot absorb the massive network/transport-level traffic that AWS Shield handles, so labeling WAF as a DDoS service conflates two distinct services.
AWS Shield: Threat detection service.
Why it's wrong here
This pairing is incorrect: AWS Shield does not serve as a threat detection service, which is the core function of Amazon GuardDuty. Shield detects and mitigates DDoS attack traffic in real time based on traffic characteristics such as volume, packet statistics, and protocol anomalies, but it does not analyze CloudTrail, DNS, or flow logs for compromise indicators. GuardDuty continuously processes those log streams and uses machine learning to generate security findings, so misattributing threat detection to Shield misrepresents the services' roles in the AWS shared responsibility model.
Go deeper
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.