SAA-C03 Design Secure Architectures Practice Question
A security engineer needs to block a specific range of malicious IP addresses from accessing an entire subnet within a VPC. The solution must ensure that the traffic is rejected before it reaches any EC2 instances. Which AWS feature should be used to implement this restriction?
⚠ Common exam trap
SAA-C03 often tests the misconception that Security Groups can block specific IPs — they cannot, because they only support allow rules; candidates who forget this choose A instead of NACLs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network Access Control Lists (NACLs)
Network ACLs are stateless, subnet-level firewalls that evaluate traffic before it reaches any EC2 instance, making them the correct tool to block a malicious IP range at the subnet boundary. Because NACLs support explicit deny rules with CIDR ranges, they can reject the traffic before it hits the instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security Groups
Why it's wrong here
Security Groups are stateful and operate at the instance level rather than the subnet level. While they can permit specific traffic, they do not support explicit 'deny' rules. To block a specific range, you would have to omit it from allow rules, which is less effective for targeted blacklisting.
- ✓
Network Access Control Lists (NACLs)
Why this is correct
NACLs provide a layer of security at the subnet level and support both allow and deny rules. By placing a deny rule with a lower rule number than the default allow rule, the security engineer can effectively block the malicious IP range for all resources within that subnet.
- ✗
AWS WAF
Why it's wrong here
AWS WAF is a web application firewall that monitors HTTP and HTTPS requests forwarded to an ALB, API Gateway, or AppSync. While it can block IPs, it operates at Layer 7 and is not designed to protect an entire subnet at the network layer like a NACL.
- ✗
AWS Shield Standard
Why it's wrong here
AWS Shield Standard is a managed Distributed Denial of Service protection service that is automatically enabled for all AWS customers. It protects against common infrastructure layer attacks but does not provide a mechanism for users to manually block specific IP ranges at the subnet level.
Visual reference
About these practice questions
One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.