DOP-C02 Security and Compliance Practice Question
A company runs a critical application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to block traffic from known malicious IP addresses before it reaches the ALB. What is the MOST effective approach?
⚠ Common exam trap
DOP-C02 often tests the misconception that security groups can deny traffic or that network ACLs are the primary tool for blocking IPs at the ALB, when in fact AWS WAF is the correct service for Layer 7 IP blocking on ALB.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS WAF with an IP set rule to block the malicious IP addresses.
AWS WAF is the only service in the list that operates at Layer 7 and integrates natively with ALB, allowing IP set rules to block traffic before it reaches the application. An IP set rule in WAF explicitly matches source IPs and takes a block action, which is exactly what the security team requires. WAF is also managed and scalable, so it can handle large IP lists without impacting ALB performance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS WAF with an IP set rule to block the malicious IP addresses.
Why this is correct
AWS WAF is the correct layer 7 filtering solution because it natively integrates with Application Load Balancers and provides managed IP sets that can be populated with the malicious source IPs. Through a Web ACL rule referencing the IP set, WAF blocks requests from those addresses before they reach the ALB, without affecting legitimate traffic. IP sets can be updated dynamically via API or Security Automation, making them practical for handling frequently changing attacker IP lists while providing access to AWS-managed rule groups for additional application-layer protection.
- ✗
Configure network ACLs on the ALB's subnet to block the malicious IPs.
Why it's wrong here
Network ACLs are stateless and evaluate traffic at the subnet boundary, meaning a rule that denies inbound traffic from a malicious IP must be paired with a corresponding outbound rule to drop return traffic for that same IP, otherwise response packets are not filtered. Because NACLs apply to every resource in the ALB's subnet, they cannot selectively protect the ALB from non-HTTP traffic destined to other instances in the same subnet, and they offer no application-layer awareness such as inspecting HTTP headers or URI patterns. Managing a dynamic list of malicious IPs in NACL rules also requires carefully ordered rule numbers and manual updates, which is less scalable and operations-friendly than a WAF IP set.
- ✗
Use AWS Network Firewall to inspect and block traffic at the VPC level.
Why it's wrong here
AWS Network Firewall operates at the VPC level to inspect traffic through stateful inspection and deep packet inspection, but it lacks the native integration with AWS WAF's managed rule sets designed specifically for Layer 7 protection of an ALB. While this service is the correct choice for implementing fine-grained egress filtering or inspecting non-HTTP protocols across a subnet, it does not provide the specific IP reputation list management required to filter malicious web traffic at the application edge.
- ✗
Configure security groups to deny inbound traffic from the malicious IP addresses.
Why it's wrong here
Security groups are stateful and only support allow rules; there is no way to write an explicit deny rule for a specific malicious IP address. To partially block a single IP, you would have to rewrite the inbound allow rules to enumerate every permitted source CIDR while omitting the malicious one, which becomes unmanageable when the list of bad actors changes frequently or when legitimate traffic comes from many diverse sources. Additionally, security groups associated with an ALB protect the ENIs but are not designed for layer 7 traffic inspection, so this approach does not give you the ability to filter based on request attributes like URI, query string, or headers—capabilities that WAF provides natively.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.