ANS-C01 Network Security, Compliance and Governance Practice Question
A security engineer is configuring Network Access Control Lists (NACLs) for a VPC with multiple subnets. The engineer wants to block SSH access (port 22) from a specific IP range 10.0.0.0/8 to the entire VPC CIDR (172.16.0.0/16). What is the most effective approach?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add inbound and outbound NACL rules denying SSH from 10.0.0.0/8
NACLs are stateless, so to block SSH from 10.0.0.0/8 to the entire VPC, both inbound and outbound rules are needed. Option A correctly adds both rules. Option B is incorrect because security groups are stateful and only allow traffic; they cannot deny. Option C is incorrect because an inbound rule alone does not block return traffic. Option D is incorrect because security groups cannot block outbound traffic based on destination IP effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add inbound and outbound NACL rules denying SSH from 10.0.0.0/8
Why this is correct
Correct. NACLs are stateless, so to block SSH traffic from 10.0.0.0/8 to the VPC CIDR, you must add both an inbound rule denying SSH from that source and an outbound rule denying SSH to that source as return traffic will be seen as a new flow.
- ✗
Add a security group rule to deny inbound SSH from 10.0.0.0/8
Why it's wrong here
Incorrect. Security groups are stateful and cannot be used to deny traffic; they only support allow rules. Also, a security group rule cannot explicitly deny traffic from a specific IP range.
- ✗
Add an inbound NACL rule denying SSH from 10.0.0.0/8
Why it's wrong here
Incorrect. Adding only an inbound NACL rule denies incoming SSH but does not block the return traffic (outbound). Since NACLs are stateless, both directions must be explicitly denied.
- ✗
Add an outbound security group rule denying SSH to 10.0.0.0/8
Why it's wrong here
Incorrect. Security groups are stateful and work at the instance level. They cannot block traffic based on destination IP in an outbound rule easily, and they only allow, not deny.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.