Layer WAF, Inspector, and GuardDuty across an API Gateway API and a legacy EC2 API

Answer Correct answer: C — Use WAF on the API Gateway API, Inspector to analyze the legacy EC2 API, and GuardDuty to monitor for malicious access.

A company hosts its primary API on AWS by using an Amazon API Gateway API and AWS Lambda functions that contain the logic for the API methods. The company’s internal applications use the API for core functionality and business logic. The company’s customers use the API to access data from their accounts. Several customers also have access to a legacy API that is running on a single standalone Amazon EC2 instance. The company wants to increase the security for these APIs to better prevent denial of service (DoS) attacks, check for vulnerabilities, and guard against common exploits. What should a solutions architect do to meet these requirements?

  1. Use AWS WAF to protect both APIs. Configure Amazon Inspector to analyze the legacy API. Configure Amazon GuardDuty to monitor for malicious attempts to access the APIs.
  2. Use AWS WAF to protect the API Gateway API. Configure Amazon Inspector to analyze both APIs. Configure Amazon GuardDuty to block malicious attempts to access the APIs.
  3. Use AWS WAF to protect the API Gateway API. Configure Amazon Inspector to analyze the legacy API. Configure Amazon GuardDuty to monitor for malicious attempts to access the APIs. Correct Answer
  4. Use AWS WAF to protect the API Gateway AP! Configure Amazon Inspector to protect the legacy API. Configure Amazon GuardDuty to block malicious attempts to access the APIs.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Each service has a distinct, non-overlapping job here: WAF filters malicious HTTP requests at the API Gateway layer, Inspector scans the EC2 host for vulnerabilities, and GuardDuty detects malicious activity through CloudTrail and flow logs as a monitoring function rather than a blocking one.

The primary API is API Gateway plus Lambda, and several customers also reach a legacy API on a single standalone EC2 instance. The goal is stronger protection against denial of service, vulnerability scanning, and common exploits across both entry points.

Writing GuardDuty as a blocking control. GuardDuty is a threat detection service that generates findings, and it is not an inline enforcement point, so describing it as blocking attempts misstates what it can do. The same applies to describing Inspector as protecting the API rather than scanning it.

Community Discussion (7 comments)

ebbff63 👍 10 Selected: C
GuardDuty only monitors but doesn't block malicious attempts. So answer is C
Helpnosense 👍 6 Selected: C
Not A because the question only say "Several customers also have access to a legacy API that is running on a single standalone Amazon EC2 instance." There is no ALB or cloudfront mentioned so WAF can't be attached to EC2 directly.
0b43291 👍 1 Selected: C
The correct answer is Option C: Use AWS WAF to protect the API Gateway API. Configure Amazon Inspector to analyze the legacy API. Configure Amazon GuardDuty to monitor for malicious attempts to access the APIs. Option C is the right choice because it directly addresses the requirement of increasing security for the API Gateway API by using AWS WAF to protect it from DoS attacks, vulnerabilities, and exploits. It also correctly suggests using Amazon Inspector to assess the security posture of the EC2 instance hosting the legacy API, and configures Amazon GuardDuty to monitor for malicious attempts across both APIs. In contrast, Option A does not explicitly mention protecting the API Gateway API and incorrectly suggests using Inspector to analyze the legacy API application itself.
Danm86 👍 1
Option C seems to be correct. In Option B, its mentioned AWS inspector to analyze both the gateway API and EC2 API. AWS inspector cannot directly monitor gateway API, it requires additional WAF configuration for it.
gfhbox0083 👍 1
C, for sure. AWS GuardDuty is a monitoring and threat detection service and does not directly block malicious activities. GuardDuty is designed to continuously monitor and analyze your AWS accounts and workloads for potential threats using machine learning, anomaly detection, and integrated threat intelligence.
mifune 👍 2 Selected: A
"The company wants to increase the security for these APIs to better prevent denial of service (DoS) attacks, check for vulnerabilities, and guard against common exploits.", so I understand that we have to protect BOTH, and GuardDuty does not block anything... The answer for me is A
zapper1234 👍 1
B becuase this protects both API's

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS WAF protects the API Gateway API against denial of service, known vulnerability exploits, and malicious request patterns, which is exactly the first requirement. The legacy API runs on a raw EC2 instance with no load balancer in front of it, so WAF cannot be attached to it, and Amazon Inspector is the service that analyzes the EC2 instance for vulnerabilities such as unintended network reachability and OS vulnerabilities. GuardDuty monitors for malicious attempts to access the APIs and produces findings for the security team. The three services map one-to-one onto the three stated security goals.

Why the Other Options Are Wrong

A: WAF cannot protect a standalone EC2 instance because there is no ALB or CloudFront distribution in front of it to attach the web ACL to, so protecting both APIs with WAF is not possible as described. B: Inspector cannot analyze an API Gateway API, since it scans compute and packages rather than API endpoints, and GuardDuty does not block malicious attempts, it detects and reports them. D: Inspector does not protect the legacy API, it scans it, and GuardDuty still does not block.

Community Comment Notes

The community voted 89 to 1 for C. The decisive arguments were that GuardDuty monitors but does not block, and that the question mentions no load balancer in front of the legacy EC2 instance, which means WAF has nothing to attach to for that API.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide