nerdexam
Amazon

SCS-C02 · Question #327

A company hosts a popular web application that connects to an Amazon RDS MySQL DB instance running in a private VPC subnet that was created with default ACL settings. The IT Security department has a

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #327. The question stem and answer options stay visible for context.

Submitted by hans_de· Mar 6, 2026Infrastructure Security

Question

A company hosts a popular web application that connects to an Amazon RDS MySQL DB instance running in a private VPC subnet that was created with default ACL settings. The IT Security department has a suspicion that a DDos attack is coming from a suspecting IP. How can you protect the subnets from this attack?

Options

  • AChange the Inbound Security Groups to deny access from the suspecting IP
  • BChange the Outbound Security Groups to deny access from the suspecting IP
  • CChange the Inbound NACL to deny access from the suspecting IP
  • DChange the Outbound NACL to deny access from the suspecting IP

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#NACL#DDoS mitigation#IP blocking#stateless rules
Full SCS-C02 Practice