A company is seeing access requests by some suspicious IP addresses. The security team discovers the requests are from different IP addresses under the same CIDR range. What should a solutions architect recommend to the team?
A.
Add a rule in the inbound table of the security to deny the traffic from that CIDR range.
B.
Add a rule in the outbound table of the security group to deny the traffic from that CIDR range.
C.
Add a deny rule in the inbound table of the network ACL with a lower number than other rules.
D.
Add a deny rule in the outbound table of the network ACL with a lower rule number than other rules.
I agree, the answer is C. Security groups are deny by default. Network ACLs by default allow everything outbound and everything inbound and you would create a dent rule with a lower number than all other rules so that it takes precedence.
Explanation:
You can only create deny rules with network ACLs, it is not possible with security groups.
Network ACLs process rules in order from the lowest numbered rules to the highest until they reach
and allow or deny. The following table describes some of the differences between security groups
and network ACLs
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
rob_724
Highly Voted 3 years, 8 months agolavy
3 years, 8 months agoaguy9
3 years, 7 months agobanjojoe
3 years, 7 months agoPaitan
Highly Voted 3 years, 8 months agoreve666
Most Recent 3 years agocraycomm
3 years, 7 months agoNkd
3 years, 7 months agokarthisena
3 years, 7 months agoIdrisAWS
3 years, 7 months agoAbdullah777
3 years, 7 months agosyu31svc
3 years, 7 months agoKK_uniq
3 years, 7 months agomryala
3 years, 7 months agoAnkitrathi85
3 years, 7 months agoAEN
3 years, 7 months agoDanny_Choi
3 years, 7 months agoElias23
3 years, 7 months agoarunchu
3 years, 7 months agosflix
3 years, 7 months agoyoungoose
3 years, 7 months ago