AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A company is hosting a public-facing web application on AWS using Amazon EC2 instances behind an Application Load Balancer (ALB). The EC2 instances are in private subnets, and the ALB is in public subnets. The security team requires that all traffic to the EC2 instances must originate from the ALB and that no other inbound traffic is allowed. How should the security groups be configured?

  1. AThe ALB security group allows inbound traffic from the EC2 security group on port 80/443. The EC2 security group allows inbound traffic from 0.0.0.0/0 on port 80/443.
  2. BThe ALB security group allows inbound traffic from 0.0.0.0/0 on port 80/443. The EC2 security group allows inbound traffic from 0.0.0.0/0 on port 80/443.
  3. CThe ALB security group allows inbound traffic from 0.0.0.0/0 on port 80/443. The EC2 security group allows inbound traffic from the ALB's security group on port 80/443.
  4. DBoth the ALB and EC2 security groups allow inbound traffic only from the VPC CIDR on port 80/443.
Show answer & explanation

Correct answer: C. The ALB security group allows inbound traffic from 0.0.0.0/0 on port 80/443. The EC2 security group allows inbound traffic from the ALB's security group on port 80/443.

To ensure traffic to EC2 instances originates only from the ALB, the EC2 security group should reference the ALB's security group as the source. The ALB, being public-facing, must accept traffic from 0.0.0.0/0.

Why the other options are wrong

  • A. This configuration is incorrect; the ALB needs to receive traffic from the internet, not from the EC2 instances. Also, allowing 0.0.0.0/0 to EC2 is a security risk.
  • B. Allowing 0.0.0.0/0 to EC2 instances in private subnets exposes them directly to the internet, violating the security requirement.
  • D. Restricting traffic to the VPC CIDR for the ALB would prevent external users from accessing the web application.

ALB & EC2 Private Subnet Security Groups

To secure EC2 instances behind an ALB in private subnets, the ALB's security group allows public inbound traffic, while the EC2 instances' security group only allows inbound traffic from the ALB's security group.

  • ALB resides in public subnets, EC2 in private.
  • ALB security group allows inbound from 0.0.0.0/0 on application ports.
  • EC2 security group allows inbound from ALB's security group on application ports.
  • Ensures EC2 instances are not directly exposed to the internet.

Memory trick: ALB Accepts All, EC2 Accepts ALB Only.

More Design Secure Architectures questions