AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard

A company is hosting a public-facing web application on AWS. They need to ensure that the application's underlying EC2 instances are only accessible from the Application Load Balancer (ALB) and that no direct internet access is allowed to the instances. Additionally, the instances need to make outbound connections to third-party APIs. Which network configuration correctly implements these security requirements?

  1. APlace ALB and EC2 instances in public subnets, configure EC2 security groups to allow traffic only from ALB's security group, and route internet traffic through an Internet Gateway.
  2. BPlace ALB in public subnets and EC2 instances in private subnets, configure EC2 security groups to allow traffic only from ALB's security group, and use a NAT Gateway for outbound internet access.
  3. CPlace ALB in private subnets and EC2 instances in private subnets, use a VPC endpoint for inbound traffic to ALB, and a NAT Gateway for outbound internet access.
  4. DPlace ALB in public subnets and EC2 instances in private subnets, configure network ACLs to block all inbound traffic to EC2 instances except from the ALB, and use an Internet Gateway for outbound access.
Show answer & explanation

Correct answer: B. Place ALB in public subnets and EC2 instances in private subnets, configure EC2 security groups to allow traffic only from ALB's security group, and use a NAT Gateway for outbound internet access.

Placing the ALB in public subnets allows it to receive internet traffic. Placing EC2 instances in private subnets ensures no direct internet access. Configuring EC2 security groups to only accept traffic from the ALB's security group restricts inbound flow. A NAT Gateway in a public subnet allows instances in private subnets to initiate outbound internet connections, fulfilling all requirements securely.

Why the other options are wrong

  • A. Placing EC2 instances in public subnets exposes them directly to the internet, violating the 'no direct internet access' requirement, even with security group rules.
  • C. Placing the ALB in private subnets means it cannot receive public internet traffic directly. A VPC endpoint is for private access to AWS services, not for making an internal ALB publicly accessible.
  • D. While the subnet placement is correct, relying solely on Network ACLs (stateless) for inbound traffic to EC2 from ALB is less flexible and harder to manage than security groups (stateful). More importantly, an Internet Gateway directly attached to private subnets would provide direct inbound internet access to EC2 (if routes allow), violating the requirement. NAT Gateway is needed for *outbound only* internet access from private subnets.

ALB & EC2 Private Subnet

A common secure architecture involves placing an Application Load Balancer in public subnets and EC2 instances in private subnets, using security groups and a NAT Gateway for controlled access.

  • ALB in public subnets for public access.
  • EC2 instances in private subnets for no direct internet access.
  • Security groups restrict traffic between ALB and EC2.
  • NAT Gateway enables outbound internet from private subnets.

Memory trick: ALB: Access Layer, Backend Secure

More Design Secure Architectures questions