A company needs to block potential botnet command-and-control traffic originating from any Amazon EC2 instances in its AWS environment. Which solution will satisfy this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Amazon Route 53 Resolver DNS Firewall. Add a rule to a rule group that uses the AWSManagedDomainsBotnetCommandandControl managed domain list and set the action to block..
Why this is the answer
The correct solution is to use Amazon Route 53 Resolver DNS Firewall. This service allows you to filter and block DNS queries originating from your VPCs. By adding a rule to a rule group that utilizes the AWSManagedDomainsBotnetCommandandControl managed domain list and setting the action to BLOCK, you can effectively prevent EC2 instances from resolving known botnet command-and-control domains, thereby blocking this type of traffic. AWS Shield Advanced primarily protects against DDoS attacks and does not specifically target botnet command-and-control traffic at the DNS level for outbound connections. AWS WAF Bot Control is designed for protecting web applications (e.g., EC2 instances behind an Application Load Balancer) from common bot traffic, not for blocking outbound botnet C2 communications. AWS Systems Manager can configure instances, but it's not a native network-level botnet C2 blocking solution.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed