How to Block Botnet Command and Control Traffic from EC2 Instances?

A company needs to protect against potential botnet command and control traffic from any Amazon EC2 instances that is in in the company’s AWS Environment. Which solution will meet these requirements?

  1. Use AWS Shield Advanced. Activate Shield Advanced protections on the EC2 instances to filter and block botnet traffic.
  2. Use Amazon Route 53 Resolver DNS Firewall. Add a rule to a rule group to use the AWSManagedDomainsBotnetCommandandControl managed domain list with an action to block botnet traffic. Source Reference Answer
  3. Use AWS WAF Bot Control. Configure a managed rule group that uses an AWS managed rule set to block botnet traffic.
  4. Use AWS Systems Manager. Run a Systems Manager Automation runbook on the EC2 instances to configure the instances to block botnet traffic.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you understand that botnet C2 traffic is often identified at the DNS query level; the common trap is choosing a DDoS or web-application firewall service that does not specifically manage outbound DNS to malicious domains.

The recommended solution for blocking botnet command and control (C2) traffic from EC2 instances is Amazon Route 53 Resolver DNS Firewall using the AWSManagedDomainsBotnetCommandandControl managed domain list. Community consensus strongly supports answer B, citing its automated, scalable, and DNS-level filtering approach.

A common incorrect choice is AWS Shield Advanced (option A), because it is a DDoS protection service, but it does not filter or block DNS queries to botnet C2 domains. Similarly, AWS WAF Bot Control (option C) focuses on HTTP(S) web traffic, not EC2-to-DNS outbound communication.

Community Discussion (7 comments)

AzureDP900 👍 2 Selected: B
It provides a proactive and automated way to block known botnets and their command and control traffic.
woorkim 👍 2 Selected: B
Amazon Route 53 Resolver DNS Firewall with the AWSManagedDomainsBotnetCommandandControl managed rule group: Scalable and Managed: Automatically updates the list of known botnet domains. Preemptive Blocking: Prevents EC2 instances from resolving malicious domains. Low Operational Overhead: Easy to implement and maintain.
luisgu 👍 3 Selected: B
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/resolver-dns-firewall-managed-domain-lists.html
cas_tori 👍 1 Selected: B
this is B
Cacheirez 👍 2 Selected: B
The question talks about "botnet command and control traffic". The most common and effective way to intercept such traffic is at the DNS level, where many botnets rely on domain names to communicate with their C2 servers. The Amazon Route 53 Resolver DNS Firewall is specifically designed to block DNS queries to known malicious domains, including those used for botnet C2 traffic. If it was application-level traffic AWS WAF Bot Control would apply.
[Removed] 👍 1
B. his service allows you to filter and block DNS queries for known malicious domains, including those associated with botnets. By using the AWSManagedDomainsBotnetCommandandControl managed domain list, you can specifically target and block DNS queries that attempt to reach botnet command and control servers.
jhon648274 👍 1
Correct answer should be B - this avoids instances from responding / connecting to malicious controllers

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Amazon Route 53 Resolver DNS Firewall is specifically designed to filter DNS queries made from resources in your VPC. By adding a rule group that contains the AWS managed domain list AWSManagedDomainsBotnetCommandandControl and setting the action to block, any DNS resolution attempt made by an EC2 instance to a known botnet C2 domain will be denied. This approach is proactive and automated because the list is continuously maintained by AWS, and it prevents EC2 instances from even resolving malicious domains. As commenter [3] notes, it offers scalable, managed, preemptive blocking with low operational overhead.

Why the Other Options Are Wrong

AWS Shield Advanced (A) is a DDoS protection service; it does not filter DNS queries or block domain resolution to botnet C2 servers. AWS WAF Bot Control (C) operates at the application layer and inspects HTTP(S) requests, but botnet C2 traffic from EC2 instances is often generated by custom protocols or DNS, so WAF is not the right layer. AWS Systems Manager (D) can run automation runbooks, but it is not a purpose-built service for continuously blocking botnet C2 domain resolution across your fleet; it would require custom scripts and would not provide managed threat intelligence.

Community Comment Notes

Comments on the exam question are unanimous in favor of B (100% of votes). Commenter [4] points out that the most effective way to intercept botnet C2 traffic is at the DNS level, because many botnets rely on domain names to communicate with their controllers. Commenter [2] adds that the solution is proactive and automated, while commenter [1] provides the official AWS documentation link for DNS Firewall managed domain lists. The discussion reinforces that for such scenarios, DNS Firewall is the go-to AWS service.

Official Reference

Exam Strategy

When you see a question about botnet command and control, immediately consider DNS-level controls. Route 53 Resolver DNS Firewall with AWS managed domain lists is the intended answer because it blocks resolution to known malicious domains, and it is easier to implement than configuring OS-level firewall rules.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide