Add a network ACL Deny for the port and source IP to block the suspicious traffic
A company deployed an Amazon EC2 instance to a VPC on AWS. A recent alert indicates that the EC2 instance is receiving a suspicious number of requests over an open TCP port from an external source. The TCP port remains open for long periods of time. The company's security team needs to stop all activity to this port from the external source to ensure that the EC2 instance is not being compromised. The application must remain available to other users. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
NACLs support explicit Deny and are evaluated before security groups, so a Deny for the port+source IP stops the suspicious traffic while the instance stays available to legitimate users. Removing the port from the SG inbound rules (B) would also block legitimate users; security groups cannot Deny (C is invalid); a new NACL denying all egress from the instance (D) would break the app's own outbound traffic. A is correct.
A single EC2 instance is getting suspicious traffic on an open TCP port from an external source, and the app must stay available to others. Security groups are stateful and can only allow (no explicit deny), so the precise block is a network ACL Deny rule for that port and source IP on the instance's subnet—stateless and immediate, and scoped to one instance so other users are unaffected.
Editing the security group to remove the port (B)—that blocks all inbound on that port, including legitimate users, violating 'app must remain available.' Trying to add a Deny in a security group (C)—security groups are allow-only, they have no deny entries. Creating a new NACL that denies all egress (D) breaks the instance's outbound traffic. A is the targeted control.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.