Skip to content
BytePatterns

CLF-C02 · Domain 2: Security and Compliance · 30% of the exam

Task 2.4: Identify components and resources for security.

The security services and where each one fits: web application firewall, DDoS protection, threat detection, vulnerability scanning, and where AWS publishes security guidance.

Study it

  • Security services: GuardDuty, Inspector, Security Hub, Shield, WAF, Firewall Manager, Trusted Advisor

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

An online store runs behind an Application Load Balancer. It wants to block HTTP requests that try to inject SQL commands through its search form before they reach the application. Which service should it use?

  1. AAWS Shield
  2. BAmazon GuardDuty
  3. CAmazon Inspector
  4. DAWS WAF
Show the answer and why
  • AAWS Shield

    Incorrect

    Shield protects against distributed denial of service (DDoS) attacks. It does not inspect requests for SQL injection.

  • BAmazon GuardDuty

    Incorrect

    GuardDuty is a threat detection service that analyzes logs and raises findings. It does not sit in front of the load balancer filtering requests.

  • CAmazon Inspector

    Incorrect

    Inspector scans workloads for software vulnerabilities and unintended network exposure. It does not block incoming requests.

  • DAWS WAF

    Correct

    AWS WAF is a web application firewall for HTTP(S) requests to resources such as an Application Load Balancer, and its SQL database managed rule group blocks request patterns associated with SQL injection.

Filtering individual web requests by what they contain is a web application firewall's job. Shield handles floods of traffic; GuardDuty and Inspector detect and report rather than block.

Question 2 · choose 1

A media company's website on Amazon CloudFront already receives the automatic protection against common network-layer DDoS attacks that AWS provides at no additional cost. Before a major live event, it wants expanded DDoS protection for the distribution and the option to escalate to AWS experts during an attack. What should it do?

  1. AEnable Amazon Inspector
  2. BEnable Amazon GuardDuty
  3. CSubscribe to AWS Shield Advanced for the distribution
  4. DNothing more is available beyond the automatic protection
Show the answer and why
  • AEnable Amazon Inspector

    Incorrect

    Inspector scans workloads for software vulnerabilities and unintended network exposure. It does not mitigate DDoS attacks.

  • BEnable Amazon GuardDuty

    Incorrect

    GuardDuty detects suspicious activity in an account and raises findings. It does not absorb or mitigate attack traffic.

  • CSubscribe to AWS Shield Advanced for the distribution

    Correct

    Shield Advanced is the paid subscription that adds expanded DDoS protection to the resources you protect, with ways to escalate to AWS when you need expert help.

  • DNothing more is available beyond the automatic protection

    Incorrect

    The automatic protection covers common volumetric attacks; Shield Advanced exists for higher levels of protection.

Every AWS customer gets the automatic, no-cost DDoS protection. Shield Advanced is the upgrade for critical applications that need more, including help from AWS during an event.

Question 3 · choose 1

A company with 60 accounts in AWS Organizations wants to define its AWS WAF rules and security group rules once, and have them applied automatically to every account, including accounts that join later. Which service should it use?

  1. AAWS Config
  2. BAWS Shield Advanced
  3. CAmazon GuardDuty
  4. DAWS Firewall Manager
Show the answer and why
  • AAWS Config

    Incorrect

    AWS Config records configurations and evaluates them against rules. It does not deploy firewall rules to accounts.

  • BAWS Shield Advanced

    Incorrect

    Shield Advanced adds DDoS protection to the resources you protect. It is not a way to manage WAF and security group rules across accounts.

  • CAmazon GuardDuty

    Incorrect

    GuardDuty detects threats from account activity and logs. It does not manage firewall rules.

  • DAWS Firewall Manager

    Correct

    With Firewall Manager you set up protections such as AWS WAF rules and security group rules once, and it applies them across your accounts and resources, even as new ones are added.

One rule set, many accounts, applied automatically to newcomers: that is Firewall Manager's job in an organization.

Question 4 · choose 1

A security team wants to run the same third-party firewall software it uses on premises inside its AWS account, deploy it in a few clicks, and have the charges appear on its AWS bill. Where should it look?

  1. AAWS Marketplace
  2. BAWS Artifact
  3. CAmazon Inspector
  4. DAWS Trusted Advisor
Show the answer and why
  • AAWS Marketplace

    Correct

    AWS Marketplace is a curated catalog of third-party software, including security products, that you can deploy quickly; its charges appear on your AWS bill.

  • BAWS Artifact

    Incorrect

    Artifact provides AWS's own compliance reports and agreements, not third-party software.

  • CAmazon Inspector

    Incorrect

    Inspector is AWS's own vulnerability management service. It is not a place to find or buy third-party products.

  • DAWS Trusted Advisor

    Incorrect

    Trusted Advisor inspects your environment and recommends improvements. It does not sell or deploy third-party software.

Third-party security tools, from firewalls to managed WAF rules, are found, bought and deployed through AWS Marketplace and billed with the rest of the account.

Question 5 · choose 1

A company wants an AWS service that inspects its account against best practices and points out security gaps — for example, that multi-factor authentication is not enabled for the root user. Which service does this?

  1. AAWS Artifact
  2. BAWS Trusted Advisor
  3. CAmazon Macie
  4. DAWS Shield
Show the answer and why
  • AAWS Artifact

    Incorrect

    Artifact provides AWS's own compliance reports and agreements. It does not inspect your account.

  • BAWS Trusted Advisor

    Correct

    Trusted Advisor inspects your environment and recommends actions to close security gaps, and it has a security check that flags a root user without MFA.

  • CAmazon Macie

    Incorrect

    Macie discovers and helps protect sensitive data in Amazon S3. It does not review account settings such as root user MFA.

  • DAWS Shield

    Incorrect

    Shield protects against DDoS attacks. It does not review your configuration.

Trusted Advisor is AWS's best-practice checker for a running account, across cost, performance, security and fault tolerance; how many checks you get depends on your support plan.

Practise domain 2 →Practise all domains →