Set the existing WAF web ACL default action to Block and allow the office IP set at priority 0

Answer Correct answer: D — set the existing web ACL default to Block and allow the office IP address set at priority 0.

A company has proprietary data available by using an Amazon CloudFront distribution. The company needs to ensure that the distribution is accessible by only users from the corporate office that have a known set of IP address ranges. An AWS WAF web ACL is associated with the distribution and has a default action set to Count. Which solution will meet these requirements with the LEAST operational overhead?

  1. Create a new regex pattern set. Add the regex pattern set to a new rule group. Create a new web ACL that has a default action set to Block. Associate the web ACL with the CloudFront distribution. Add a rule that allows traffic based on the new rule group.
  2. Create an AWS WAF IP address set that matches the corporate office IP address range. Create a new web ACL that has a default action set to Allow. Associate the web ACL with the CloudFront distribution. Add a rule that allows traffic from the IP address set.
  3. Create a new regex pattern set. Add the regex pattern set to a new rule group. Set the default action on the existing web ACL to Allow. Add a rule that has priority 0 that allows traffic based on the regex pattern set.
  4. Create a WAF IP address set that matches the corporate office IP address range. Set the default action on the existing web ACL to Block. Add a rule that has priority 0 that allows traffic from the IP address set. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Two things follow from the least-overhead requirement. Reusing the existing web ACL instead of creating a new one and re-associating it removes work, which f4b18ba identified as the key efficiency point. Within that web ACL, an IP address set matches the known corporate IP ranges directly, whereas a regex pattern set would have to express IP ranges as patterns, which is unnecessary (D). Setting the default action to Block with an explicit allow at priority 0 expresses allow-list semantics, so teo2157 noted that priority 0 is the highest-priority rule and therefore evaluated before the default.

Access must be limited to users from the corporate office, which is a known set of source IP addresses, so an AWS WAF IP address set is the matching construct rather than a regex pattern set. Because a web ACL is already associated with the distribution, the least-overhead change is to modify that existing web ACL rather than create a new one: set its default action to Block so everything not explicitly allowed is denied, and add a rule with priority 0 that allows traffic originating from the corporate office IP address set. Priority 0 places the allow rule ahead of any other rule so the office traffic is admitted before the default block applies.

Creating a new web ACL with a default action of Allow and an IP address set rule (B) — a default action of Allow means anything not matching the IP set is permitted, so the restriction the requirement asks for is not enforced; the default must be Block with an explicit allow. Using regex pattern sets for IP ranges (A and C) — a regex pattern set is for matching request patterns such as URIs or headers, not for expressing known IP address ranges, which is what an IP address set is designed for; f4b18ba identified the IP address set as the right construct for matching specific source IP addresses. Setting the existing web ACL default to Allow and adding a priority 0 allow rule (C) — with a default action of Allow, unmatched traffic is still permitted, so this does not restrict access to the office ranges.

Community Discussion (4 comments)

Srikantha 👍 1 Selected: D
Goal: Allow access only from specific IP ranges (corporate office), and block everything else. WAF IP set: This is the right tool for matching specific source IP addresses. Default action = Block: Ensures all traffic is blocked unless explicitly allowed. Rule priority 0 (highest priority): Ensures that corporate IPs are evaluated first and allowed. Uses existing web ACL: Minimizes overhead by not needing to create a new ACL.
teo2157 👍 3 Selected: D
Agreee with D as prioty 0 is the highest priority rule
f4b18ba 👍 3 Selected: D
Using Existing Web ACL: This approach leverages the existing web ACL, minimizing the need to create a new one, which reduces operational overhead. IP Address Set: By creating a WAF IP address set that matches the corporate office IP address range, you precisely define which IP addresses are allowed access. Blocking by Default: Setting the default action to Block ensures that only traffic from the defined IP addresses is allowed, meeting the security requirement. High Priority Rule: Adding a high-priority rule (priority 0) to allow traffic from the IP address set ensures that legitimate traffic from the corporate office is not blocked.
uncledana 👍 3 Selected: D
The requirements are: 1. Restrict access to the CloudFront distribution to users from a known set of IP address ranges (the corporate office). 2. Minimize operational overhead. 3. Use the existing AWS WAF web ACL, which has the default action set to Count. Option D: Create a WAF IP address set that matches the corporate office IP address range. Set the default action on the existing web ACL to Block. Add a rule that has priority 0 that allows traffic from the IP address set.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is to restrict the CloudFront distribution to users from the corporate office, identified by a known set of IP address ranges, using the least operational overhead, and a web ACL is already associated with the distribution. The correct solution therefore modifies that existing web ACL rather than building a new one. An AWS WAF IP address set is created to match the corporate office IP ranges, which is precisely what Srikantha identified as the right construct for matching specific source IP addresses. The existing web ACL's default action is then set to Block, so every request that is not explicitly allowed is denied, and a rule with priority 0 is added that allows traffic from the IP address set; because priority 0 is evaluated first, as teo2157 noted, office traffic is admitted before the default block applies (D). f4b18ba confirmed the efficiency argument, that reusing the existing web ACL minimizes the need to create a new one and thereby reduces operational overhead, and uncledana summarized that the option satisfies restricting access to the known ranges, minimizing overhead, and using the existing web ACL. D is the correct answer.

Why the Other Options Are Wrong

A creates a regex pattern set, adds it to a new rule group, creates a new web ACL with a default action of Block, associates that new web ACL with the distribution, and adds a rule allowing traffic based on the new rule group. This creates a new web ACL and re-associates it with the distribution rather than modifying the existing one, which is the extra work the least-overhead requirement asks to avoid, and f4b18ba identified reuse of the existing web ACL as the efficiency point. It also uses a regex pattern set, which is designed for matching request patterns rather than for expressing known IP address ranges, where an IP address set is the appropriate construct. B creates an IP address set and a new web ACL whose default action is Allow, then adds a rule allowing traffic from the IP set. The default action of Allow is decisive: any request that does not match the office IP set is still permitted, so the requirement to allow only office users is not enforced. C creates a regex pattern set, sets the default action on the existing web ACL to Allow, and adds a priority 0 rule allowing traffic matching the pattern set. This correctly reuses the existing web ACL and correctly orders the rule, but the default action of Allow again means unmatched traffic is permitted, and the pattern set is the wrong construct for IP ranges. D is correct.

Community Comment Notes

Community voted D unanimously. Srikantha explained that an IP address set is the right tool for matching the corporate office source IP ranges and that a default action of Block ensures everything else is denied. teo2157 agreed, noting that priority 0 is the highest-priority rule and is therefore evaluated before the default action. f4b18ba emphasized that using the existing web ACL minimizes operational overhead, which is the decisive tiebreaker against options A and B that create a new web ACL. uncledana summarized the three requirements, restricting access to the known IP ranges, minimizing operational overhead, and using the existing web ACL, all of which option D satisfies. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide