In SAP-C02 Domain 2, security and reliability are not separate concerns. A system designed securely is also more reliable. This post covers the security layers represented by WAF, Shield, and GuardDuty, the criteria for choosing between NLB and ALB, Auto Scaling policy types, and loose coupling architectures based on SQS and SNS — all tied to real exam scenarios.
WAF — Rule Types and Attachment Targets
AWS WAF is a web application firewall that defends against L7 HTTP/HTTPS attacks. You attach a WebACL to an ALB, API Gateway, CloudFront distribution, or AppSync API. Direct attachment to an EC2 instance is not possible.
Three WAF rule types appear frequently in the exam. Rate-based Rules automatically block a source IP that sends more than a threshold number of requests within a five-minute window. They are the primary defense against HTTP Flood attacks. Geo Match conditions allow or block access based on the request's country of origin, using the MaxMind GeoIP database with automatic updates. IP Set rules let you specify explicit CIDR ranges to allow or block.
Know the difference between WAF Geo Match and Route 53 Geolocation routing. WAF Geo Match blocks traffic. Route 53 Geolocation routes traffic to a specific endpoint — it does not block.
WAF logs can be streamed in real time to S3 via Kinesis Data Firehose. Logs include source IP, country code, matched rule, and action (ALLOW or BLOCK). For regulatory long-term retention requirements, apply S3 Object Lock in Compliance mode.
Shield Advanced — L7 DDoS Defense and Cost Protection
Shield Standard is included with every AWS account at no charge. It automatically defends against L3/L4 volumetric attacks.
Shield Advanced is a paid service starting at roughly $3,000 per month. It adds 24/7 DDoS Response Team (DRT) support for L7 DDoS attacks, cost protection that credits excessive AWS charges caused by a DDoS attack, and always-on detection with automatic mitigation. Consider Shield Advanced when large-scale attacks are a realistic risk or when high availability is core to the business, as with financial services or gaming platforms.
The standard pattern for layered DDoS defense is Shield (L3/L4) plus CloudFront (edge traffic absorption) plus WAF (L7 rule-based blocking). When the goal is minimum cost with baseline protection, choose Shield Standard (free) plus CloudFront plus WAF.
NLB vs ALB — Selection Criteria
| Item | NLB | ALB | |------|-----|-----| | Layer | L4 (TCP/UDP/TLS) | L7 (HTTP/HTTPS) | | Fixed IP | Elastic IP supported | Not supported | | Source IP preservation | Client IP passed through directly | X-Forwarded-For header required | | Security Groups | Not supported on NLB itself (use EC2 SG) | Supported | | Routing | IP:Port based | URL path / Host header / query params | | WAF attachment | Not supported | Supported |
NLB passes the client source IP directly to the EC2 instance. When IP-based access control is needed, you control access through the security group on the EC2 instances behind NLB. You cannot attach a security group directly to an NLB.
Choose NLB for UDP-based services (game servers, DNS) or when fixed IPs are required. Choose ALB when you need HTTP-based routing, WAF attachment, or Host-header-based routing.
!NLB versus ALB selection criteria
Encryption — KMS CMK, SSE, TLS, VPC Endpoints
For encryption at rest, KMS CMK (Customer Managed Key) is the key concept. S3 offers three server-side encryption options: SSE-S3 (AWS-managed keys), SSE-KMS (KMS CMK), and SSE-C (customer-provided keys). Adding a bucket policy condition that denies requests where is false enforces HTTPS-only access.
For encryption in transit, TLS is the mechanism. When CloudFront communicates with an origin over HTTPS, the CN or SAN on the origin certificate must exactly match the CloudFront origin domain name. Self-signed certificates are not accepted; a publicly trusted CA-signed certificate is required.
VPC Endpoints let you access AWS services without going through the internet. Gateway Endpoints are dedicated to S3 and DynamoDB, use a routing-table-based mechanism, and have no additional cost. Interface Endpoints create an ENI and incur an hourly charge. When you need to access S3 from an internet-restricted environment, use a Gateway VPC Endpoint.
CloudHSM provides dedicated hardware security modules that not even AWS can access. M of N quorum authentication requires approval from M out of N administrators before sensitive operations can execute. Choose CloudHSM when PCI DSS HSM requirements must be met.
Auto Scaling Policies — Target Tracking, Step, Predictive
Auto Scaling provides three dynamic policy types.
Target Tracking automatically adjusts capacity to maintain a specified metric at a target value. You set the goal — for example CPU utilization at 70% or 1000 requests per target — and AWS calculates the scaling actions. It is the simplest and most recommended approach.
Step Scaling defines different scaling increments for different alarm conditions. For example: add 1 instance when CPU is between 70–80%, add 2 when between 80–90%, add 4 when above 90%. This is useful when traffic spike patterns are predictable.
Predictive Scaling uses machine learning to analyze historical traffic patterns and pre-scales capacity in advance of anticipated demand. It is effective for workloads with regular load variations, such as a daily lunch-hour traffic spike.
DynamoDB Scheduled Actions work on the same principle. You pre-scale capacity at a specific time to bypass the latency of reactive scaling.
Loose Coupling — SQS, SNS, Step Functions
Loose coupling reduces direct dependencies between system components so that the failure of one component does not cascade to the whole system.
SQS Standard Queue guarantees at-least-once delivery but does not guarantee ordering. SQS FIFO Queue provides ordering guarantees and exactly-once processing but has a baseline throughput limit of 300 TPS. Enabling high-throughput mode raises this to up to 70,000 TPS.
The SNS fan-out pattern delivers a single event to multiple SQS queues simultaneously. Delivering S3 events directly to Lambda creates a risk of event loss when concurrency limits are exceeded. Switching to SNS → multiple SQS queues → Lambda means SQS acts as a buffer that preserves messages when Lambda cannot process them immediately. The SQS Dead Letter Queue (DLQ) stores failed messages separately for later reprocessing.
ASG Lifecycle Hooks give in-flight work time to complete before an instance terminates. The instance enters Terminating:Wait state. Either the application sends a completion signal or the heartbeat timeout expires before termination proceeds. For an instance processing 60-second financial transactions, set heartbeat_timeout to 120 seconds.
Multi-AZ High Availability Patterns
RDS Multi-AZ uses synchronous replication, making RPO nearly zero, with automatic failover completing in under 30 seconds. RDS Read Replica uses asynchronous replication and is intended for read query distribution. These serve different purposes. Multi-AZ is for availability; Read Replica is for read performance.
Aurora Multi-AZ maintains six copies across three AZs in its shared storage architecture. Because Replicas share the cluster volume, automatic promotion to Primary takes only a few tens of seconds.
ElastiCache Redis in a Multi-AZ replication group improves availability and serves as a distributed session store shared across instances. Eliminating Sticky Sessions lets Auto Scaling freely add and remove instances without disrupting user sessions.
Route 53 Failover routing combined with Calculated Health Checks is the engine of automatic DNS failover. If a secondary record has no Health Check configured, it is always considered Healthy and failover cannot work correctly.
Exam Key Points
"Can WAF be attached directly to EC2" -- No, only ALB / CloudFront / API Gateway
"Block traffic from a specific country" -- WAF Geo Match (Route 53 Geolocation routes, it does not block)
"Automatically block HTTP Flood attacks" -- WAF Rate-based Rules
"Shield Advanced adds over Standard" -- DRT support plus cost protection plus always-on detection
"NLB source IP preservation" -- client IP passed directly (ALB needs X-Forwarded-For)
"Apply security group directly to NLB" -- not possible, use EC2 security groups behind NLB
"Access S3 in an internet-restricted environment" -- S3 Gateway VPC Endpoint (no extra cost)
"HSM that even AWS cannot access plus quorum authentication" -- CloudHSM plus M of N
"Simplest Auto Scaling policy" -- Target Tracking
"Pre-scale to bypass reactive scaling latency" -- Predictive Scaling or Scheduled Action
"Prevent event loss when SNS sends directly to Lambda at high volume" -- SNS to SQS buffer to Lambda
"SQS FIFO baseline throughput" -- 300 TPS (70,000 TPS with high-throughput mode)
"RDS Multi-AZ purpose" -- availability (Read Replica is for read performance)