Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to block traffic from a specific IP address range from accessing an Application Load Balancer (ALB). Which AWS feature should be used?

⚠ Common exam trap

SCS-C02 often tests the difference between security groups, NACLs, and WAF, and candidates may incorrectly choose security groups because they think they can block IPs, but security groups only allow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS WAF

AWS WAF is the correct feature to block traffic from a specific IP address range from accessing an Application Load Balancer. WAF integrates directly with ALB and allows you to create rules based on IP addresses, which can be used to allow or block requests. Network ACLs and security groups operate at the network layer and are not specific to ALB traffic inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network ACL

    Why it's wrong here

    Network ACLs are stateless filters applied at the VPC subnet boundary, not on the Application Load Balancer itself. While you could add a deny rule for a specific IP in the subnet's NACL, that would also impact every other resource in the subnet and force you to manage ephemeral port ranges for the ALB's health checks and responses. They operate at Layers 3 and 4, so they cannot inspect HTTP/HTTPS traffic or provide application-level blocking, making AWS WAF a more direct fit.

  • ✗

    Security Group for the ALB

    Why it's wrong here

    Security groups are stateful firewalls that only contain allow rules; there is no explicit deny action, so you cannot specify a single IP to block while allowing everyone else. If the ALB's security group does not have an allow rule for the traffic, it is implicitly denied, but adding a 'block' rule for an IP is not supported. To block specific IP addresses while continuing to allow other clients, you must use AWS WAF's IP set rules, not a security group.

  • ✗

    Route53

    Why it's wrong here

    Amazon Route 53 is a DNS resolution service that maps domain names to IP addresses; it does not sit in the data path and cannot block or allow traffic from a specific source IP. Even a 'failover' or 'blackhole' record would only affect clients who re-resolve the DNS name and would not stop direct traffic to the ALB's IP address. Real-time IP filtering requires a Layer 7 web application firewall, not DNS manipulation.

  • ✓

    AWS WAF

    Why this is correct

    AWS WAF is the correct service because it attaches as a web access control list (web ACL) directly to the Application Load Balancer. You can create an IP set match rule to block the specific IPv4 or IPv6 address before the request reaches the ALB, and WAF inspects each HTTP/HTTPS request at Layer 7. It also offers managed rules, rate-based rules, and geo-matching for more granular traffic control, and its integration is a one-click attachment to ALBs.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.