SCS-C02 Infrastructure Security Practice Question
A company has a VPC with a public subnet and a private subnet. The public subnet hosts a NAT instance (Amazon Linux) that provides internet access to instances in the private subnet. The security team notices that the NAT instance is receiving high inbound traffic on port 22 from an external IP address. The team wants to block this traffic at the network layer without affecting other traffic. What is the most effective solution?
⚠ Common exam trap
A common mix-up: candidates choose security groups (Option B) because they are familiar with them, but the question explicitly requires blocking at the network layer, and NACLs are the correct layer 3/4 subnet-level control, while security groups are instance-level and stateful, making them unsuitable for this specific requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a network ACL rule on the public subnet to deny inbound traffic from the specific IP on port 22.
A network ACL (NACL) operates at the subnet level (layer 3/4) and is stateless, meaning it can explicitly deny inbound traffic from a specific IP on port 22 before it reaches the NAT instance. This blocks the traffic at the network layer without affecting other traffic, as NACLs evaluate rules in order and deny rules override allow rules for the specified traffic. Unlike security groups, NACLs do not require the traffic to first reach the instance, making them ideal for blocking unwanted traffic at the subnet boundary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Move the NAT instance to a private subnet and use a NAT gateway instead.
Why it's wrong here
Moving the NAT instance to a private subnet and replacing it with a NAT gateway would not restrict the specific attacker IP on port 22. A NAT gateway is a managed service that performs IP forwarding but provides no configurable deny rules for inbound management traffic, and moving the instance out of the public subnet would actually prevent it from receiving a public IP or serving as an internet gateway. This architectural change neither filters the malicious source IP nor blocks SSH, so the attack path remains open.
- ✗
Modify the security group attached to the NAT instance to block inbound SSH from the specific IP.
Why it's wrong here
Security groups are stateful and only support allow rules, so you cannot create an explicit deny for a single source IP address. Removing the inbound SSH rule to block the attacker would also deny SSH to all other legitimate administrators, because security groups lack the precedence-based deny logic needed to selectively block one address. Therefore, modifying the NAT instance's security group cannot satisfy the requirement to block only the specific IP.
- ✗
Use AWS WAF to block the IP address.
Why it's wrong here
AWS WAF is an application-layer firewall that inspects HTTP/S requests and is typically associated with CloudFront or an Application Load Balancer. SSH traffic on TCP port 22 is not HTTP/S and operates at the transport layer, so WAF cannot see or filter these connections to a NAT instance. Even if WAF were deployed, it lacks the protocol awareness needed to evaluate or block inbound SSH sessions.
- ✓
Add a network ACL rule on the public subnet to deny inbound traffic from the specific IP on port 22.
Why this is correct
A network ACL is a stateless, subnet-level firewall that supports explicit DENY rules with numeric precedence, allowing you to block traffic from a specific source IP on a specific port. Adding a deny rule for that IP and port 22 on the public subnet's NACL will be evaluated before traffic reaches the NAT instance, while still permitting all other inbound traffic. This is the correct approach because NACLs operate at the VPC edge and support the granular, deny-based filtering that security groups cannot provide.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.