AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An operations team must ensure that EC2 instances in a production VPC cannot resolve domains that the security team lists as malicious. The solution must record every blocked DNS query in Amazon CloudWatch Logs and require minimal ongoing maintenance. Which approach meets these requirements?
Deploy a Route 53 Resolver inbound endpoint and forward queries to an EC2-based DNS proxy that filters the malicious domains using an open-source blacklist.
Create a Route 53 Resolver DNS Firewall rule group that blocks the malicious domains, associate the group with the VPC for outbound DNS traffic, and enable Resolver DNS Firewall logging to CloudWatch Logs.
Attach an AWS WAF web ACL to the application's load balancer with rules that block requests whose Host header matches the malicious domains.
Add deny entries to the VPC's network ACL that block outbound TCP and UDP traffic on port 53 to the IP addresses of the malicious domains.
Route 53 Resolver DNS Firewall provides domain-based protection without changing the instances' DNS settings. Creating a deny rule group and associating it with the VPC on the outbound direction automatically blocks lookups to the specified domains. When firewall logging is enabled, each blocked or allowed query is delivered to a CloudWatch Logs log group, giving the audit trail the team needs. AWS WAF only inspects HTTP(S) traffic, not the DNS lookups generated by the instances. Network ACLs cannot evaluate domain names and would require constant IP list updates. Forwarding queries to a self-managed filtering proxy adds operational overhead that the requirement aims to avoid.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Route 53 Resolver DNS Firewall?
Open an interactive chat with Bash
How does enabling Resolver DNS Firewall logging help with auditing?
Open an interactive chat with Bash
Why can't Network ACLs block specific domains like the DNS Firewall?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .