Courseiva
Infrastructure Security →easyMultiple Select

SCS-C02 Infrastructure Security Practice Question

Which TWO AWS services are designed to provide DDoS protection? (Choose 2.)

⚠ Common exam trap

Test-takers frequently confuse monitoring or auditing services (VPC Flow Logs, CloudTrail, Config) with active security controls, but only AWS Shield and AWS WAF provide direct DDoS mitigation capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF

AWS WAF (Option D) is a web application firewall that helps protect web applications from common web exploits that could affect application availability, compromise security, or consume excessive resources. It integrates with Amazon CloudFront, Application Load Balancer, and API Gateway to filter and monitor HTTP(S) requests, providing protection against layer 7 DDoS attacks such as SQL injection and cross-site scripting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture IP traffic information for elastic network interfaces, recording metadata such as source/destination addresses, ports, protocol, and whether the packet was accepted or rejected. This is strictly a monitoring and forensic tool: it operates passively, has no ability to filter, block, or absorb malicious traffic, and therefore cannot mitigate or prevent DDoS attacks. It can only help you understand traffic patterns after an incident has occurred.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity across your AWS account, capturing actions taken on the control plane such as creating an EC2 instance, modifying IAM roles, or calling other AWS service APIs. DDoS attacks primarily target the data plane at the network or application layer, not HTTP-based AWS service API endpoints (and even API abuse would not be stopped by simply logging it). CloudTrail provides auditability and post-incident forensics, but it has no inline mechanism to detect or block volumetric or application-layer attack traffic.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config continuously records resource configuration changes and evaluates them against compliance rules, such as detecting overly permissive security group rules or exposed load balancer settings. While AWS Config can help identify misconfigurations that might make infrastructure more vulnerable to DDoS (for example, a wide-open network ACL), it does not inspect live traffic, execute blocking actions, or absorb attack traffic in real time. Its purpose is configuration governance and compliance, not DDoS mitigation.

  • ✓

    AWS WAF

    Why this is correct

    AWS WAF is a web application firewall that protects at Layer 7 by inspecting HTTP(S) requests and filtering malicious traffic before it reaches your application. You can use rate-based rules to limit the number of requests from a given IP address, block known attacker IP sets, and mitigate HTTP floods, SQL injection, or cross-site scripting attempts. This directly addresses application-layer DDoS attacks, which consume application resources by sending large volumes of web requests, and it is a core component for ongoing protection of web-facing workloads.

  • ✓

    AWS Shield Standard

    Why this is correct

    AWS Shield Standard is an always-on, automatic protection service that defends all AWS customers against network and transport layer (Layer 3 and 4) DDoS attacks, including SYN floods, UDP floods, and reflection attacks. It is integrated into AWS infrastructure and requires no configuration, providing baseline protection at no additional cost for all AWS resources. Because it operates transparently at the network level, it does not inspect application-layer content, so it must be paired with AWS WAF for full DDoS protection across the OSI stack.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.