Set the existing WAF web ACL default action to Block and allow the office IP set at priority 0
A company has proprietary data available by using an Amazon CloudFront distribution. The company needs to ensure that the distribution is accessible by only users from the corporate office that have a known set of IP address ranges. An AWS WAF web ACL is associated with the distribution and has a default action set to Count. Which solution will meet these requirements with the LEAST operational overhead?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Two things follow from the least-overhead requirement. Reusing the existing web ACL instead of creating a new one and re-associating it removes work, which f4b18ba identified as the key efficiency point. Within that web ACL, an IP address set matches the known corporate IP ranges directly, whereas a regex pattern set would have to express IP ranges as patterns, which is unnecessary (D). Setting the default action to Block with an explicit allow at priority 0 expresses allow-list semantics, so teo2157 noted that priority 0 is the highest-priority rule and therefore evaluated before the default.
Access must be limited to users from the corporate office, which is a known set of source IP addresses, so an AWS WAF IP address set is the matching construct rather than a regex pattern set. Because a web ACL is already associated with the distribution, the least-overhead change is to modify that existing web ACL rather than create a new one: set its default action to Block so everything not explicitly allowed is denied, and add a rule with priority 0 that allows traffic originating from the corporate office IP address set. Priority 0 places the allow rule ahead of any other rule so the office traffic is admitted before the default block applies.
Creating a new web ACL with a default action of Allow and an IP address set rule (B) — a default action of Allow means anything not matching the IP set is permitted, so the restriction the requirement asks for is not enforced; the default must be Block with an explicit allow. Using regex pattern sets for IP ranges (A and C) — a regex pattern set is for matching request patterns such as URIs or headers, not for expressing known IP address ranges, which is what an IP address set is designed for; f4b18ba identified the IP address set as the right construct for matching specific source IP addresses. Setting the existing web ACL default to Allow and adding a priority 0 allow rule (C) — with a default action of Allow, unmatched traffic is still permitted, so this does not restrict access to the office ranges.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is to restrict the CloudFront distribution to users from the corporate office, identified by a known set of IP address ranges, using the least operational overhead, and a web ACL is already associated with the distribution. The correct solution therefore modifies that existing web ACL rather than building a new one. An AWS WAF IP address set is created to match the corporate office IP ranges, which is precisely what Srikantha identified as the right construct for matching specific source IP addresses. The existing web ACL's default action is then set to Block, so every request that is not explicitly allowed is denied, and a rule with priority 0 is added that allows traffic from the IP address set; because priority 0 is evaluated first, as teo2157 noted, office traffic is admitted before the default block applies (D). f4b18ba confirmed the efficiency argument, that reusing the existing web ACL minimizes the need to create a new one and thereby reduces operational overhead, and uncledana summarized that the option satisfies restricting access to the known ranges, minimizing overhead, and using the existing web ACL. D is the correct answer.Why the Other Options Are Wrong
A creates a regex pattern set, adds it to a new rule group, creates a new web ACL with a default action of Block, associates that new web ACL with the distribution, and adds a rule allowing traffic based on the new rule group. This creates a new web ACL and re-associates it with the distribution rather than modifying the existing one, which is the extra work the least-overhead requirement asks to avoid, and f4b18ba identified reuse of the existing web ACL as the efficiency point. It also uses a regex pattern set, which is designed for matching request patterns rather than for expressing known IP address ranges, where an IP address set is the appropriate construct. B creates an IP address set and a new web ACL whose default action is Allow, then adds a rule allowing traffic from the IP set. The default action of Allow is decisive: any request that does not match the office IP set is still permitted, so the requirement to allow only office users is not enforced. C creates a regex pattern set, sets the default action on the existing web ACL to Allow, and adds a priority 0 rule allowing traffic matching the pattern set. This correctly reuses the existing web ACL and correctly orders the rule, but the default action of Allow again means unmatched traffic is permitted, and the pattern set is the wrong construct for IP ranges. D is correct.Community Comment Notes
Community voted D unanimously. Srikantha explained that an IP address set is the right tool for matching the corporate office source IP ranges and that a default action of Block ensures everything else is denied. teo2157 agreed, noting that priority 0 is the highest-priority rule and is therefore evaluated before the default action. f4b18ba emphasized that using the existing web ACL minimizes operational overhead, which is the decisive tiebreaker against options A and B that create a new web ACL. uncledana summarized the three requirements, restricting access to the known IP ranges, minimizing operational overhead, and using the existing web ACL, all of which option D satisfies. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →