AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A software company is deploying a new web application using AWS Elastic Beanstalk. The application needs to connect to an Amazon RDS MySQL database. To enhance security, the company wants to restrict database access only to the Elastic Beanstalk instances. How should a Solutions Architect configure the security groups to achieve this?

  1. ACreate an RDS security group allowing inbound MySQL traffic from the Elastic Beanstalk environment's security group.
  2. BConfigure the RDS security group to allow inbound MySQL traffic from the Elastic Beanstalk environment's public IP address.
  3. CCreate an EC2 security group for the Elastic Beanstalk environment and configure it to allow outbound MySQL traffic to the RDS endpoint.
  4. DCreate an EC2 security group for the Elastic Beanstalk environment and allow inbound MySQL traffic from 0.0.0.0/0.
Show answer & explanation

Correct answer: A. Create an RDS security group allowing inbound MySQL traffic from the Elastic Beanstalk environment's security group.

By referencing the Elastic Beanstalk environment's security group in the RDS security group, you create a dynamic, secure connection. The RDS instance will only accept traffic originating from instances associated with that specific Elastic Beanstalk security group, ensuring tight access control without hardcoding IP addresses.

Why the other options are wrong

  • B. Elastic Beanstalk instances can have dynamic public IP addresses, making this approach unreliable and requiring frequent updates. It also doesn't leverage the security group concept effectively.
  • C. The outbound rules on the Elastic Beanstalk security group control what the instances can connect to, but the inbound rules on the RDS security group control what can connect to the database. Both are needed, but the core access control is on the RDS inbound rule.
  • D. Allowing 0.0.0.0/0 would expose the database to the entire internet, which is a major security risk.

Security Group Referencing

A method to allow traffic between AWS resources by specifying a source or destination security group, rather than IP addresses.

  • Simplifies network access control between AWS services.
  • Dynamically updates as instances are added or removed from the referenced security group.
  • Enhances security by avoiding hardcoded IP addresses.

Memory trick: Security Groups Talk, RDS Unlocks.

More Design Secure Architectures questions