Amazon
SOA-C02 · Question #86
Malicious traffic is reaching company web servers from a single IP address located in another country. The SysOps Administrator is tasked with blocking this IP address. How should the Administrator…
The correct answer is B. Edit the network access control list for the web server subnet and add a deny entry for the IP. We need to restrict one ip so Geo restriction is false. A false because you cant deny trafic for one ip in Security Group
Submitted by deeparc· Mar 30, 2026Security and Compliance
Question
Malicious traffic is reaching company web servers from a single IP address located in another country. The SysOps Administrator is tasked with blocking this IP address. How should the Administrator implement the restriction?
Options
- AEdit the security group for the web servers and add a deny entry for the IP address
- BEdit the network access control list for the web server subnet and add a deny entry for the IP
- CEdit the VPC route table to route the malicious IP address to a black hole
- DUse Amazon CloudFront's geo restriction feature to block traffic from the IP address
How the community answered
(30 responses)- A3% (1)
- B77% (23)
- C13% (4)
- D7% (2)
Explanation
We need to restrict one ip so Geo restriction is false. A false because you cant deny trafic for one ip in Security Group
Topics
#NACL#IP blocking#security groups#network security
Community Discussion
No community discussion yet for this question.