CV0-004 Security Practice Question
A startup is deploying a web application on AWS and wants to protect it from common Layer 7 attacks such as SQL injection and cross-site scripting. The application runs behind an Application Load Balancer, and the team wants a managed service that can be deployed quickly with minimal configuration. Which AWS service should they use?
⚠ Common exam trap
Many exam-takers confuse Shield Advanced with WAF — Shield mitigates DDoS at the network layer, while WAF inspects application requests for injection and scripting attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS WAF
AWS WAF is purpose-built to inspect HTTP(S) traffic and block Layer 7 attacks like SQL injection and XSS using managed rule groups. It integrates natively with Application Load Balancer and can be deployed in minutes, satisfying the startup's need for a managed, low-configuration solution. The other services address DDoS, threat detection, or network-layer filtering, not application payload protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS WAF
Why this is correct
AWS WAF is a managed web application firewall that inspects HTTP(S) requests at Layer 7 and can block SQL injection and cross-site scripting using AWS Managed Rules. It integrates directly with Application Load Balancer, CloudFront, and API Gateway, and can be deployed quickly with preconfigured rule groups, matching the startup's need for minimal configuration.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced provides enhanced DDoS protection at Layers 3 and 4, with additional mitigation for some Layer 7 volumetric attacks. However, it does not inspect application payloads for SQL injection or cross-site scripting, so it cannot block those specific web application exploits. It is a DDoS mitigation service, not a WAF.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty is a threat detection service that analyzes logs such as VPC Flow Logs, CloudTrail, and DNS logs to identify malicious activity. It does not sit inline with application traffic and cannot block SQL injection or XSS requests. It provides alerts rather than prevention, so it does not meet the protection requirement.
- ✗
AWS Network Firewall
Why it's wrong here
AWS Network Firewall is a managed stateful firewall for VPC traffic that operates at Layers 3 and 4 with some Layer 7 inspection via Suricata-compatible rules. It is not designed to protect HTTP applications from SQL injection or XSS in the way AWS WAF is, and it requires more configuration, so it does not fit the quick-managed-service requirement.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.