An Auto Scaling group fronts EC2 instances behind an ALB and the application is receiving malicious traffic originating from a single public IP. You must block that IP address from reaching the application. Which solution will block the IP effectively?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an IP set in AWS WAF that contains the malicious IP, create a web ACL with an IP match rule set to BLOCK, and associate the web ACL with the ALB..
Why this is the answer
AWS WAF (Web Application Firewall) is designed to protect web applications from common web exploits and bots. By creating an IP set with the malicious IP address and a web ACL with a BLOCK rule, AWS WAF can effectively prevent traffic from that specific IP from reaching the ALB and, consequently, the application. Adding a security group rule to the ALB is incorrect because security groups are stateful and primarily allow traffic; they do not have explicit deny rules for specific IPs in the same way WAF does. Amazon Detective is a security service for investigating potential threats, not for actively blocking traffic. AWS Resource Access Manager (RAM) is used for sharing AWS resources between accounts, not for traffic filtering.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed