nerdexam
Amazon

CLF-C02 · Question #448

A company notices suspicious network activity against an application that is running on a fleet of Amazon EC2 instances. The suspicious activity is coming from a single IP address. Which AWS service s

The correct answer is D. AWS WAF. AWS WAF (Web Application Firewall) allows you to create custom rules to block or allow traffic based on specific patterns, such as IP addresses. In this case, the company can create a rule to block access from the suspicious IP address and protect the EC2 instances from potential

Submitted by satoshi_tk· Mar 6, 2026Security and Compliance

Question

A company notices suspicious network activity against an application that is running on a fleet of Amazon EC2 instances. The suspicious activity is coming from a single IP address. Which AWS service should the company use to block access from this IP address?

Options

  • AAWS Shield
  • BAWS Config
  • CAmazon GuardDuty
  • DAWS WAF

How the community answered

(30 responses)
  • A
    13% (4)
  • B
    3% (1)
  • C
    7% (2)
  • D
    77% (23)

Explanation

AWS WAF (Web Application Firewall) allows you to create custom rules to block or allow traffic based on specific patterns, such as IP addresses. In this case, the company can create a rule to block access from the suspicious IP address and protect the EC2 instances from potential

Community Discussion

No community discussion yet for this question.

Full CLF-C02 Practice