Add a network ACL Deny for the port and source IP to block the suspicious traffic

Answer Correct answer: A — add a network ACL Deny for the port and source IP to block the suspicious traffic while keeping the app available.

A company deployed an Amazon EC2 instance to a VPC on AWS. A recent alert indicates that the EC2 instance is receiving a suspicious number of requests over an open TCP port from an external source. The TCP port remains open for long periods of time. The company's security team needs to stop all activity to this port from the external source to ensure that the EC2 instance is not being compromised. The application must remain available to other users. Which solution will meet these requirements?

  1. Update the network ACL that is attached to the subnet that is associated with the EC2 instance. Add a Deny statement for the port and the source IP addresses. Correct Answer
  2. Update the elastic network interface security group that is attached to the EC2 instance to remove the port from the inbound rule list.
  3. Update the elastic network interface security group that is attached to the EC2 instance by adding a Deny entry in the inbound list for the port and the source IP addresses.
  4. Create a new network ACL for the subnet. Deny all traffic from the EC2 instance to prevent data from being removed.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

NACLs support explicit Deny and are evaluated before security groups, so a Deny for the port+source IP stops the suspicious traffic while the instance stays available to legitimate users. Removing the port from the SG inbound rules (B) would also block legitimate users; security groups cannot Deny (C is invalid); a new NACL denying all egress from the instance (D) would break the app's own outbound traffic. A is correct.

A single EC2 instance is getting suspicious traffic on an open TCP port from an external source, and the app must stay available to others. Security groups are stateful and can only allow (no explicit deny), so the precise block is a network ACL Deny rule for that port and source IP on the instance's subnet—stateless and immediate, and scoped to one instance so other users are unaffected.

Editing the security group to remove the port (B)—that blocks all inbound on that port, including legitimate users, violating 'app must remain available.' Trying to add a Deny in a security group (C)—security groups are allow-only, they have no deny entries. Creating a new NACL that denies all egress (D) breaks the instance's outbound traffic. A is the targeted control.

Community Discussion (4 comments)

TareDHakim 👍 1 Selected: A
the question indicates it is a single instance on the network so no other workloads will be impacted.
imymoco 👍 1
I vote D
div05jkjl 👍 1
A is the answer
VPNalumni 👍 1
Agree A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A network ACL is stateless and supports explicit Deny rules, so adding a Deny for the suspicious source IP and port on the subnet NACL blocks that traffic immediately. Because it is scoped to the port and source, legitimate users on other ports or sources are unaffected, and the instance stays available—meeting both requirements.

Why the Other Options Are Wrong

B removes the port from the SG inbound rules, which would also cut off legitimate users of that port, violating availability. C proposes a Deny entry in a security group, but security groups are stateful allow-only and have no deny rules. D creates a new NACL denying all egress from the instance, which would break the application's own outbound communication. A is correct.

Community Comment Notes

Community voted A (100). Commenters noted it is a single instance, so an NACL Deny for the port and source IP will not impact other workloads, and that security groups cannot deny. A confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide