Layer WAF, Inspector, and GuardDuty across an API Gateway API and a legacy EC2 API
A company hosts its primary API on AWS by using an Amazon API Gateway API and AWS Lambda functions that contain the logic for the API methods. The company’s internal applications use the API for core functionality and business logic. The company’s customers use the API to access data from their accounts. Several customers also have access to a legacy API that is running on a single standalone Amazon EC2 instance. The company wants to increase the security for these APIs to better prevent denial of service (DoS) attacks, check for vulnerabilities, and guard against common exploits. What should a solutions architect do to meet these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Each service has a distinct, non-overlapping job here: WAF filters malicious HTTP requests at the API Gateway layer, Inspector scans the EC2 host for vulnerabilities, and GuardDuty detects malicious activity through CloudTrail and flow logs as a monitoring function rather than a blocking one.
The primary API is API Gateway plus Lambda, and several customers also reach a legacy API on a single standalone EC2 instance. The goal is stronger protection against denial of service, vulnerability scanning, and common exploits across both entry points.
Writing GuardDuty as a blocking control. GuardDuty is a threat detection service that generates findings, and it is not an inline enforcement point, so describing it as blocking attempts misstates what it can do. The same applies to describing Inspector as protecting the API rather than scanning it.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS WAF protects the API Gateway API against denial of service, known vulnerability exploits, and malicious request patterns, which is exactly the first requirement. The legacy API runs on a raw EC2 instance with no load balancer in front of it, so WAF cannot be attached to it, and Amazon Inspector is the service that analyzes the EC2 instance for vulnerabilities such as unintended network reachability and OS vulnerabilities. GuardDuty monitors for malicious attempts to access the APIs and produces findings for the security team. The three services map one-to-one onto the three stated security goals.Why the Other Options Are Wrong
A: WAF cannot protect a standalone EC2 instance because there is no ALB or CloudFront distribution in front of it to attach the web ACL to, so protecting both APIs with WAF is not possible as described. B: Inspector cannot analyze an API Gateway API, since it scans compute and packages rather than API endpoints, and GuardDuty does not block malicious attempts, it detects and reports them. D: Inspector does not protect the legacy API, it scans it, and GuardDuty still does not block.Community Comment Notes
The community voted 89 to 1 for C. The decisive arguments were that GuardDuty monitors but does not block, and that the question mentions no load balancer in front of the legacy EC2 instance, which means WAF has nothing to attach to for that API.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →