Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company has a VPC with a public subnet and a private subnet. The public subnet hosts a NAT instance (Amazon Linux) that provides internet access to instances in the private subnet. The security team notices that the NAT instance is receiving high inbound traffic on port 22 from an external IP address. The team wants to block this traffic at the network layer without affecting other traffic. What is the most effective solution?

⚠ Common exam trap

A common mix-up: candidates choose security groups (Option B) because they are familiar with them, but the question explicitly requires blocking at the network layer, and NACLs are the correct layer 3/4 subnet-level control, while security groups are instance-level and stateful, making them unsuitable for this specific requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a network ACL rule on the public subnet to deny inbound traffic from the specific IP on port 22.

A network ACL (NACL) operates at the subnet level (layer 3/4) and is stateless, meaning it can explicitly deny inbound traffic from a specific IP on port 22 before it reaches the NAT instance. This blocks the traffic at the network layer without affecting other traffic, as NACLs evaluate rules in order and deny rules override allow rules for the specified traffic. Unlike security groups, NACLs do not require the traffic to first reach the instance, making them ideal for blocking unwanted traffic at the subnet boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Move the NAT instance to a private subnet and use a NAT gateway instead.

    Why it's wrong here

    Moving the NAT instance to a private subnet and replacing it with a NAT gateway would not restrict the specific attacker IP on port 22. A NAT gateway is a managed service that performs IP forwarding but provides no configurable deny rules for inbound management traffic, and moving the instance out of the public subnet would actually prevent it from receiving a public IP or serving as an internet gateway. This architectural change neither filters the malicious source IP nor blocks SSH, so the attack path remains open.

  • ✗

    Modify the security group attached to the NAT instance to block inbound SSH from the specific IP.

    Why it's wrong here

    Security groups are stateful and only support allow rules, so you cannot create an explicit deny for a single source IP address. Removing the inbound SSH rule to block the attacker would also deny SSH to all other legitimate administrators, because security groups lack the precedence-based deny logic needed to selectively block one address. Therefore, modifying the NAT instance's security group cannot satisfy the requirement to block only the specific IP.

  • ✗

    Use AWS WAF to block the IP address.

    Why it's wrong here

    AWS WAF is an application-layer firewall that inspects HTTP/S requests and is typically associated with CloudFront or an Application Load Balancer. SSH traffic on TCP port 22 is not HTTP/S and operates at the transport layer, so WAF cannot see or filter these connections to a NAT instance. Even if WAF were deployed, it lacks the protocol awareness needed to evaluate or block inbound SSH sessions.

  • ✓

    Add a network ACL rule on the public subnet to deny inbound traffic from the specific IP on port 22.

    Why this is correct

    A network ACL is a stateless, subnet-level firewall that supports explicit DENY rules with numeric precedence, allowing you to block traffic from a specific source IP on a specific port. Adding a deny rule for that IP and port 22 on the public subnet's NACL will be evaluated before traffic reaches the NAT instance, while still permitting all other inbound traffic. This is the correct approach because NACLs operate at the VPC edge and support the granular, deny-based filtering that security groups cannot provide.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.