A single IP address is flooding a public web tier with junk requests. The security groups on the instances currently allow port 443 from anywhere, which is correct — the site is public. The team wants to block that one source address across every instance in the public subnets. What do they do?
AWS Certified Cloud Practitioner (CLF-C02), objective 3. Cloud technology and services hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
The options
Correct Add a deny rule for that address in the network ACL on the public subnets
Correct. Network ACLs evaluate numbered rules in order and are the only one of the two VPC firewalls that can express a deny, which is what 'everyone except this address' requires.
Not correct Add a deny rule for that address to the security group
Wrong, and this is the single most common misconception about security groups. They contain allow rules only; anything not allowed is already denied. There is no way to subtract one address from an allow rule.
Not correct Remove the rule that allows port 443 from 0.0.0.0/0
Wrong. That does block the attacker, along with every genuine visitor. It takes the public website offline to stop one client.
Not correct Add a route in the subnet's route table that discards traffic from that address
Wrong, and it misreads what a route table does. Routes choose a next hop by DESTINATION address. There is no source-based routing here, so you cannot route one client away.
Why
Two firewalls, and the exam separates them on four properties. Security groups: attached to the instance's network interface, stateful (return traffic is allowed automatically), allow rules only, all rules evaluated together. Network ACLs: attached to the subnet, stateless (you must permit both directions yourself), allow AND deny rules, evaluated in number order until one matches. Remember it as: the security group is a guest list, and only the network ACL can hold a blacklist. For an HTTP flood at scale, AWS WAF and AWS Shield are the purpose-built tools.
Where this comes from
- Cited
- AWS exam guide task statement 3.5
Practise this
Reading one question is not practice. The trainer will draw a set from objective 3 and space the ones you get wrong.
Practise AWS Certified Cloud Practitioner (CLF-C02)
More questions on this objective
- A team builds the same stack — a load balancer, three EC2 instances and a database — by clicking through the console once for dev, once for test and once for production. The three environments have quietly drifted apart and a bug that only appears in production took a week to trace to a missing setting. They want the stack described once, reviewed in a pull request, and applied identically to each environment. Which service does that? machine-checked
- A Python reporting job runs unattended every night. Inside its own logic it needs to list objects in an S3 bucket, read a few of them, and write a summary object back, handling failures with the program's existing retry and logging code. What is the appropriate way for that program to call AWS? machine-checked
- A small team has a Java web application and no operations staff. They want to hand AWS the application package and have it provision the instances, the load balancer and the scaling policy, while keeping the ability to inspect and adjust those resources later if they need to. Which service fits? machine-checked
- A manufacturer keeps its plant-floor control application on servers inside the factory, because production must continue when the internet link drops. Its reporting and analytics run in AWS and read the same production data. Which TWO statements about this arrangement are accurate? machine-checked
- An internal application runs on a single EC2 instance in one Availability Zone. During a power event in that Availability Zone the application was unreachable for four hours. The team wants the cheapest change that keeps it serving through the same kind of event, without moving to another Region. What should they do? machine-checked
- A German insurer is told by its regulator that customer records must remain within the European Union. Four candidate Regions can all run every service the workload needs, and one of them is noticeably cheaper per instance-hour. Which consideration settles the choice of Region first? machine-checked