Courseiva

DOP-C02 Incident and Event Response Practice Question

A company uses an Application Load Balancer (ALB) in front of a fleet of EC2 instances. The security team reports that a specific client IP address is sending malicious requests and must be blocked immediately. The ALB's security group only allows HTTP/HTTPS from 0.0.0.0/0. What is the FASTEST way to block traffic from this IP address without affecting other traffic?

⚠ Common exam trap

DOP-C02 often tests the allow-only nature of security groups and the lack of source-IP deny in ALB listener rules — the trap is assuming security groups or listener rules can block a single IP like a firewall ACL.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an AWS WAF web ACL with an IP set deny rule and associate it with the ALB.

AWS WAF with an IP set deny rule associated to the ALB is the fastest and most surgical way to block a specific client IP. WAF evaluates requests at the ALB before they reach targets, and an IP match condition with a block action takes effect within seconds without touching security groups or routing. This blocks only the offending IP while all other traffic continues normally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an AWS WAF web ACL with an IP set deny rule and associate it with the ALB.

    Why this is correct

    AWS WAF provides application-layer (Layer 7) inspection and can be associated directly with an ALB. By creating a web ACL that references an IP set containing the offending client IP and setting the default or custom rule action to 'Block', requests from that IP are denied before they reach the ALB. This is the purpose-built, scalable mechanism for IP-based blocking in front of an ALB, and it can be implemented without altering routing or security group configurations.

  • ✗

    Modify the ALB listener rules to drop requests from the client IP.

    Why it's wrong here

    ALB listener rules are used for routing decisions, not for packet filtering or traffic denial. They support conditions such as host-header, path-pattern, and source-ip, but the only available actions are forward, redirect, fixed-response, and authenticate—there is no 'drop' action. Even if you added a rule to match the client IP and returned a fixed 403 response, that would not 'drop' the request; it would still consume resources and would not behave like a deny at the network layer. This is why listener rules are not a valid mechanism for blocking IPs.

  • ✗

    Update the ALB security group to add a deny rule for the client IP address.

    Why it's wrong here

    Security groups in Amazon VPC are stateful and allow-only; they do not support explicit deny rules. You cannot add a 'deny' entry for any source IP; the only way to block traffic with a security group is to omit an allow rule, which would block all traffic, not just a specific IP. To selectively deny a client IP at the subnet or network layer, you need a network ACL (NACL), which supports both allow and deny rules. Thus, updating the ALB security group cannot achieve the desired outcome.

  • ✗

    Update the VPC route table to drop packets from the client IP.

    Why it's wrong here

    VPC route tables govern how packets are forwarded between subnets, gateways, and other network destinations, and they make decisions based solely on the destination IP address. They have no ability to filter or drop packets based on source IP, nor do they implement security rules—traffic filtering is handled by security groups and network ACLs. Changing a route table entry would redirect traffic to another target or cause a routing failure for a range of destinations, not selectively block a single client IP. Therefore, this approach is fundamentally incorrect.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company runs a web application on EC2 instances behind an ALB. The security team notices that the ALB is receiving a large number of requests from a single IP address, causing high CPU on the instances. They want to block this IP at the load balancer level without affecting other traffic. The ALB currently has a default action of forwarding to the target group. What is the MOST effective way to block this IP?

hard
  • A.Update the network ACL for the VPC subnets to deny inbound traffic from that IP.
  • B.Add a deny rule in the ALB's security group for the source IP.
  • C.Change the listener rule to forward requests from that IP to a different target group with no instances.
  • ✓ D.Create an AWS WAF web ACL with an IP match condition and associate it with the ALB.

Why D: AWS WAF (option D) remains the best answer because it is purpose-built for this, offers IP sets, logging, and rate-based rules, and is the AWS-recommended approach for IP-based blocking at the ALB. However, option C's stated reason for being wrong is inaccurate: ALB listener rules DO support a source-ip condition natively; the real flaw in option C is that it proposes routing the matched IP to an empty target group (yielding a slow/ambiguous 503) instead of the correct method of using a source-ip condition with a fixed-response action (403) or, better, AWS WAF for centralized IP-block management with logging and rate limiting.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.