How to Block Botnet Command and Control Traffic from EC2 Instances?
A company needs to protect against potential botnet command and control traffic from any Amazon EC2 instances that is in in the company’s AWS Environment. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you understand that botnet C2 traffic is often identified at the DNS query level; the common trap is choosing a DDoS or web-application firewall service that does not specifically manage outbound DNS to malicious domains.
The recommended solution for blocking botnet command and control (C2) traffic from EC2 instances is Amazon Route 53 Resolver DNS Firewall using the AWSManagedDomainsBotnetCommandandControl managed domain list. Community consensus strongly supports answer B, citing its automated, scalable, and DNS-level filtering approach.
A common incorrect choice is AWS Shield Advanced (option A), because it is a DDoS protection service, but it does not filter or block DNS queries to botnet C2 domains. Similarly, AWS WAF Bot Control (option C) focuses on HTTP(S) web traffic, not EC2-to-DNS outbound communication.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Amazon Route 53 Resolver DNS Firewall is specifically designed to filter DNS queries made from resources in your VPC. By adding a rule group that contains the AWS managed domain list AWSManagedDomainsBotnetCommandandControl and setting the action to block, any DNS resolution attempt made by an EC2 instance to a known botnet C2 domain will be denied. This approach is proactive and automated because the list is continuously maintained by AWS, and it prevents EC2 instances from even resolving malicious domains. As commenter [3] notes, it offers scalable, managed, preemptive blocking with low operational overhead.Why the Other Options Are Wrong
AWS Shield Advanced (A) is a DDoS protection service; it does not filter DNS queries or block domain resolution to botnet C2 servers. AWS WAF Bot Control (C) operates at the application layer and inspects HTTP(S) requests, but botnet C2 traffic from EC2 instances is often generated by custom protocols or DNS, so WAF is not the right layer. AWS Systems Manager (D) can run automation runbooks, but it is not a purpose-built service for continuously blocking botnet C2 domain resolution across your fleet; it would require custom scripts and would not provide managed threat intelligence.Community Comment Notes
Comments on the exam question are unanimous in favor of B (100% of votes). Commenter [4] points out that the most effective way to intercept botnet C2 traffic is at the DNS level, because many botnets rely on domain names to communicate with their controllers. Commenter [2] adds that the solution is proactive and automated, while commenter [1] provides the official AWS documentation link for DNS Firewall managed domain lists. The discussion reinforces that for such scenarios, DNS Firewall is the go-to AWS service.Official Reference
Exam Strategy
When you see a question about botnet command and control, immediately consider DNS-level controls. Route 53 Resolver DNS Firewall with AWS managed domain lists is the intended answer because it blocks resolution to known malicious domains, and it is easier to implement than configuring OS-level firewall rules.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →