Courseiva
Security →hardMultiple Choice

CV0-004 Security Practice Question

A cloud architect is designing a DDoS protection strategy for a web application hosted on AWS. The application uses an Application Load Balancer (ALB). Which service provides automatic, always-on DDoS protection at no additional cost?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Shield Standard

AWS Shield Standard provides automatic protection against common DDoS attacks for all AWS customers at no additional cost.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF filters HTTP requests against rule sets you configure, so it only blocks traffic matching those signatures rather than absorbing volumetric floods. It is tempting because WAF is the natural place to add Layer 7 filtering for an ALB, but AWS Shield Standard already supplies the automatic, no-cost DDoS protection the stem demands.

  • ✗

    AWS Network Firewall

    Why it's wrong here

    Network Firewall provides stateful inspection and filtering at the VPC level, requiring you to author and maintain rule groups; it is not automatic or always-on DDoS mitigation. It is tempting because it guards network traffic, and would suit scenarios demanding granular VPC ingress/egress control or intrusion prevention rather than volumetric attack absorption.

  • ✓

    AWS Shield Standard

    Why this is correct

    AWS Shield Standard is enabled automatically on all AWS accounts and protects against common network and transport layer DDoS attacks at no extra charge. It defends the ALB without configuration, satisfying the always-on, zero-cost constraint.

  • ✗

    AWS Shield Advanced

    Why it's wrong here

    Shield Advanced adds costed protections such as DDoS Response Team support and cost protection, so it breaches the no-additional-cost requirement. It is tempting because it genuinely delivers enhanced DDoS mitigation, and would be correct where an organisation needs advanced attack visibility, WAF included, or financial indemnity against scaling charges.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.