Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A sysadmin needs to block specific IP addresses from accessing an Application Load Balancer. Which approach is MOST efficient?

⚠ Common exam trap

SOA-C02 often tests the misconception that security groups can deny traffic; candidates must remember security groups are allow-only, and WAF is the correct service for Layer 7 IP blocking on ALB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an AWS WAF web ACL with IP set rules and associate it with the ALB.

AWS WAF is the most efficient and appropriate service for blocking specific IP addresses from accessing an Application Load Balancer. You can create an IP set with the addresses to block and associate a web ACL with the ALB. WAF operates at Layer 7 and is designed for this purpose, providing granular control and scalability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the security group for the ALB to deny traffic from those IPs.

    Why it's wrong here

    Security groups are stateful, allow-only filters; they do not support explicit deny rules. Adding a rule to 'deny' a specific IP is impossible because any traffic not explicitly allowed by an allow rule is already implicitly dropped, but you cannot create a rule that blocks one source while allowing others. The correct service for IP-level blocking on an ALB is AWS WAF, not security groups.

  • ✗

    Add a route in the VPC route table to drop traffic from those IPs.

    Why it's wrong here

    VPC route tables govern the path of network traffic based on destination CIDR blocks, not source IP addresses. They cannot be configured to drop or blackhole traffic originating from specific IPs; a route entry only dictates where packets destined for a particular network are sent. Source-IP filtering is outside the scope of routing and must be handled by security groups, NACLs, or WAF.

  • ✓

    Create an AWS WAF web ACL with IP set rules and associate it with the ALB.

    Why this is correct

    AWS WAF is the recommended service for blocking specific IP addresses at an Application Load Balancer. You create a web ACL, define an IP set with the offending addresses, and attach a rule that blocks requests matching that set, then associate the web ACL with the ALB. This provides layer-7 protection, allowing granular control over source IPs while leaving other traffic unaffected, and integrates with features like rate-based rules and managed rule groups.

  • ✗

    Update the network ACL for the ALB subnets.

    Why it's wrong here

    Network ACLs are stateless filters applied at the subnet boundary, so they require careful configuration of both inbound and outbound rules to account for response traffic. While a NACL could technically deny traffic from the IPs, it would affect every instance in the ALB's subnet, not just the load balancer, and the stateless nature makes it error-prone. For ALB-specific IP blocking, a WAF web ACL is a far cleaner and more targeted solution.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.