A single IP address is flooding a public web tier with junk requests. The security groups on the instances currently allow port 443 from anywhere, which is correct — the site is public. The team wants to block that one source address across every instance in the public subnets. What do they do?

AWS Certified Cloud Practitioner (CLF-C02), objective 3. Cloud technology and services hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct Add a deny rule for that address in the network ACL on the public subnets

Correct. Network ACLs evaluate numbered rules in order and are the only one of the two VPC firewalls that can express a deny, which is what 'everyone except this address' requires.

Not correct Add a deny rule for that address to the security group

Wrong, and this is the single most common misconception about security groups. They contain allow rules only; anything not allowed is already denied. There is no way to subtract one address from an allow rule.

Not correct Remove the rule that allows port 443 from 0.0.0.0/0

Wrong. That does block the attacker, along with every genuine visitor. It takes the public website offline to stop one client.

Not correct Add a route in the subnet's route table that discards traffic from that address

Wrong, and it misreads what a route table does. Routes choose a next hop by DESTINATION address. There is no source-based routing here, so you cannot route one client away.

Why

Two firewalls, and the exam separates them on four properties. Security groups: attached to the instance's network interface, stateful (return traffic is allowed automatically), allow rules only, all rules evaluated together. Network ACLs: attached to the subnet, stateless (you must permit both directions yourself), allow AND deny rules, evaluated in number order until one matches. Remember it as: the security group is a guest list, and only the network ACL can hold a blacklist. For an HTTP flood at scale, AWS WAF and AWS Shield are the purpose-built tools.

Where this comes from

Cited
AWS exam guide task statement 3.5

Practise this

Reading one question is not practice. The trainer will draw a set from objective 3 and space the ones you get wrong.

Practise AWS Certified Cloud Practitioner (CLF-C02)

More questions on this objective

All questions on Cloud technology and services