SCS-C02 Infrastructure Security Practice Question
Which TWO AWS services are designed to provide DDoS protection? (Choose 2.)
⚠ Common exam trap
Test-takers frequently confuse monitoring or auditing services (VPC Flow Logs, CloudTrail, Config) with active security controls, but only AWS Shield and AWS WAF provide direct DDoS mitigation capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF
AWS WAF (Option D) is a web application firewall that helps protect web applications from common web exploits that could affect application availability, compromise security, or consume excessive resources. It integrates with Amazon CloudFront, Application Load Balancer, and API Gateway to filter and monitor HTTP(S) requests, providing protection against layer 7 DDoS attacks such as SQL injection and cross-site scripting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture IP traffic information for elastic network interfaces, recording metadata such as source/destination addresses, ports, protocol, and whether the packet was accepted or rejected. This is strictly a monitoring and forensic tool: it operates passively, has no ability to filter, block, or absorb malicious traffic, and therefore cannot mitigate or prevent DDoS attacks. It can only help you understand traffic patterns after an incident has occurred.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API activity across your AWS account, capturing actions taken on the control plane such as creating an EC2 instance, modifying IAM roles, or calling other AWS service APIs. DDoS attacks primarily target the data plane at the network or application layer, not HTTP-based AWS service API endpoints (and even API abuse would not be stopped by simply logging it). CloudTrail provides auditability and post-incident forensics, but it has no inline mechanism to detect or block volumetric or application-layer attack traffic.
- ✗
AWS Config
Why it's wrong here
AWS Config continuously records resource configuration changes and evaluates them against compliance rules, such as detecting overly permissive security group rules or exposed load balancer settings. While AWS Config can help identify misconfigurations that might make infrastructure more vulnerable to DDoS (for example, a wide-open network ACL), it does not inspect live traffic, execute blocking actions, or absorb attack traffic in real time. Its purpose is configuration governance and compliance, not DDoS mitigation.
- ✓
AWS WAF
Why this is correct
AWS WAF is a web application firewall that protects at Layer 7 by inspecting HTTP(S) requests and filtering malicious traffic before it reaches your application. You can use rate-based rules to limit the number of requests from a given IP address, block known attacker IP sets, and mitigate HTTP floods, SQL injection, or cross-site scripting attempts. This directly addresses application-layer DDoS attacks, which consume application resources by sending large volumes of web requests, and it is a core component for ongoing protection of web-facing workloads.
- ✓
AWS Shield Standard
Why this is correct
AWS Shield Standard is an always-on, automatic protection service that defends all AWS customers against network and transport layer (Layer 3 and 4) DDoS attacks, including SYN floods, UDP floods, and reflection attacks. It is integrated into AWS infrastructure and requires no configuration, providing baseline protection at no additional cost for all AWS resources. Because it operates transparently at the network level, it does not inspect application-layer content, so it must be paired with AWS WAF for full DDoS protection across the OSI stack.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.