SOA-C02 Networking and Content Delivery Practice Question
A sysadmin needs to block specific IP addresses from accessing an Application Load Balancer. Which approach is MOST efficient?
⚠ Common exam trap
SOA-C02 often tests the misconception that security groups can deny traffic; candidates must remember security groups are allow-only, and WAF is the correct service for Layer 7 IP blocking on ALB.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an AWS WAF web ACL with IP set rules and associate it with the ALB.
AWS WAF is the most efficient and appropriate service for blocking specific IP addresses from accessing an Application Load Balancer. You can create an IP set with the addresses to block and associate a web ACL with the ALB. WAF operates at Layer 7 and is designed for this purpose, providing granular control and scalability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the security group for the ALB to deny traffic from those IPs.
Why it's wrong here
Security groups are stateful, allow-only filters; they do not support explicit deny rules. Adding a rule to 'deny' a specific IP is impossible because any traffic not explicitly allowed by an allow rule is already implicitly dropped, but you cannot create a rule that blocks one source while allowing others. The correct service for IP-level blocking on an ALB is AWS WAF, not security groups.
- ✗
Add a route in the VPC route table to drop traffic from those IPs.
Why it's wrong here
VPC route tables govern the path of network traffic based on destination CIDR blocks, not source IP addresses. They cannot be configured to drop or blackhole traffic originating from specific IPs; a route entry only dictates where packets destined for a particular network are sent. Source-IP filtering is outside the scope of routing and must be handled by security groups, NACLs, or WAF.
- ✓
Create an AWS WAF web ACL with IP set rules and associate it with the ALB.
Why this is correct
AWS WAF is the recommended service for blocking specific IP addresses at an Application Load Balancer. You create a web ACL, define an IP set with the offending addresses, and attach a rule that blocks requests matching that set, then associate the web ACL with the ALB. This provides layer-7 protection, allowing granular control over source IPs while leaving other traffic unaffected, and integrates with features like rate-based rules and managed rule groups.
- ✗
Update the network ACL for the ALB subnets.
Why it's wrong here
Network ACLs are stateless filters applied at the subnet boundary, so they require careful configuration of both inbound and outbound rules to account for response traffic. While a NACL could technically deny traffic from the IPs, it would affect every instance in the ALB's subnet, not just the load balancer, and the stateless nature makes it error-prone. For ALB-specific IP blocking, a WAF web ACL is a far cleaner and more targeted solution.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.