Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

Match each AWS service to its primary security function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Web application firewall

DDoS protection

Key management and encryption

Identity and access management

Data discovery and classification

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF: Web application firewall that protects against common web exploits.

These are core AWS security services with distinct purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS WAF: Web application firewall that protects against common web exploits.

    Why this is correct

    AWS WAF is a web application firewall that operates at Layer 7 (HTTP/S) to inspect and filter traffic destined for Amazon CloudFront, an Application Load Balancer, or Amazon API Gateway. It uses managed or custom rules to block common web exploits such as SQL injection (SQLi), cross-site scripting (XSS), excessive URI lengths, and geo-based attacks. Because it sees application-layer requests and can apply rate-based rules, it is purpose-built for web application protection, not network or transport-level attack mitigation.

  • ✓

    AWS Shield: Managed DDoS protection service.

    Why this is correct

    AWS Shield is a fully managed DDoS protection service; the always-on AWS Shield Standard is automatically enabled for all AWS customers at no cost, absorbing common network and transport-layer DDoS attacks. AWS Shield Advanced adds enhanced detection, near real-time visibility via CloudWatch metrics, and 24/7 access to the DDoS Response Team, along with cost protection against scaling-related charges. It defends against volumetric and protocol-level attacks such as SYN floods and UDP reflection attacks, making it distinct from a web application firewall.

  • ✓

    Amazon GuardDuty: Threat detection service that monitors for malicious activity.

    Why this is correct

    Amazon GuardDuty is a continuous threat detection service that consumes foundational data sources, including AWS CloudTrail management events, VPC Flow Logs, and DNS query logs. Using machine learning, anomaly detection, and curated threat intelligence feeds, it raises findings for suspicious activities like compromised credentials, cryptocurrency mining, or unusual API behavior. Unlike WAF and Shield, GuardDuty is not designed to stop attacks in real time; instead, it detects indicators of compromise so customers can investigate and remediate.

  • ✓

    AWS KMS: Managed service for creating and controlling encryption keys.

    Why this is correct

    AWS Key Management Service (KMS) is a regional, managed service used to create, store, rotate, and control the life cycle of customer master keys and, more recently, KMS keys. These keys are protected by FIPS 140-2 validated hardware security modules (HSMs) and can be used for envelope encryption, where a KMS key encrypts data keys that then encrypt customer data in services such as S3, EBS, and RDS. Access is governed by IAM and key policies, with auditability through CloudTrail, so it is fundamentally about cryptographic control, not attack filtering or DDoS defense.

  • ✗

    AWS WAF: Managed DDoS protection service.

    Why it's wrong here

    This pairing is incorrect: AWS WAF is not a managed DDoS protection service; that role belongs to AWS Shield. DDoS protection mitigates volumetric, protocol, and other attacks that target network availability, often at Layers 3 and 4, whereas WAF operates at Layer 7 and blocks specific HTTP/S request patterns. While using AWS WAF can help stop the application-layer flood component of an attack, it cannot absorb the massive network/transport-level traffic that AWS Shield handles, so labeling WAF as a DDoS service conflates two distinct services.

  • ✗

    AWS Shield: Threat detection service.

    Why it's wrong here

    This pairing is incorrect: AWS Shield does not serve as a threat detection service, which is the core function of Amazon GuardDuty. Shield detects and mitigates DDoS attack traffic in real time based on traffic characteristics such as volume, packet statistics, and protocol anomalies, but it does not analyze CloudTrail, DNS, or flow logs for compromise indicators. GuardDuty continuously processes those log streams and uses machine learning to generate security findings, so misattributing threat detection to Shield misrepresents the services' roles in the AWS shared responsibility model.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.