Courseiva
Network Security, Compliance and GovernancehardMultiple ChoiceObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A security engineer is configuring Network Access Control Lists (NACLs) for a VPC with multiple subnets. The engineer wants to block SSH access (port 22) from a specific IP range 10.0.0.0/8 to the entire VPC CIDR (172.16.0.0/16). What is the most effective approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Add inbound and outbound NACL rules denying SSH from 10.0.0.0/8

NACLs are stateless, so to block SSH from 10.0.0.0/8 to the entire VPC, both inbound and outbound rules are needed. Option A correctly adds both rules. Option B is incorrect because security groups are stateful and only allow traffic; they cannot deny. Option C is incorrect because an inbound rule alone does not block return traffic. Option D is incorrect because security groups cannot block outbound traffic based on destination IP effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Add inbound and outbound NACL rules denying SSH from 10.0.0.0/8

    Why this is correct

    Correct. NACLs are stateless, so to block SSH traffic from 10.0.0.0/8 to the VPC CIDR, you must add both an inbound rule denying SSH from that source and an outbound rule denying SSH to that source as return traffic will be seen as a new flow.

  • Add a security group rule to deny inbound SSH from 10.0.0.0/8

    Why it's wrong here

    Incorrect. Security groups are stateful and cannot be used to deny traffic; they only support allow rules. Also, a security group rule cannot explicitly deny traffic from a specific IP range.

  • Add an inbound NACL rule denying SSH from 10.0.0.0/8

    Why it's wrong here

    Incorrect. Adding only an inbound NACL rule denies incoming SSH but does not block the return traffic (outbound). Since NACLs are stateless, both directions must be explicitly denied.

  • Add an outbound security group rule denying SSH to 10.0.0.0/8

    Why it's wrong here

    Incorrect. Security groups are stateful and work at the instance level. They cannot block traffic based on destination IP in an outbound rule easily, and they only allow, not deny.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.