Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A company is using an Application Load Balancer (ALB) to route traffic to a set of EC2 instances. The security team wants to ensure that only traffic from the ALB can reach the instances. Which security group configuration should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the EC2 instance security group to allow traffic from the ALB security group.

Option C is correct because security groups can reference other security groups as a source, so the EC2 instances' security group can allow inbound traffic specifically from the ALB's security group, ensuring only ALB-forwarded traffic reaches the instances. This approach is the AWS-recommended pattern and works regardless of the ALB's changing IP addresses. Option A is wrong because ALB IP addresses are dynamic and not a stable, manageable source. Option B is wrong because network ACLs cannot reference security groups as a source; they only support CIDR-based rules. Option D is wrong because allowing HTTP from 0.0.0.0/0 exposes the instances to the entire internet, not just the ALB.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the EC2 instance security group to allow traffic from the ALB's private IP address range.

    Why it's wrong here

    Configuring the EC2 instance security group to allow traffic from the ALB's private IP address range is an unreliable approach. Application Load Balancers are managed services whose underlying Elastic Network Interfaces (ENIs) and associated private IP addresses can change dynamically due to scaling events, maintenance, or failovers. Hardcoding these ephemeral IP ranges in the instance security group creates a brittle configuration that would frequently break, leading to intermittent connectivity issues and significant operational overhead.

  • ✗

    Configure the network ACL for the EC2 instance subnet to allow traffic from the ALB security group.

    Why it's wrong here

    Configuring the network ACL for the EC2 instance subnet to allow traffic from the ALB security group is incorrect because Network ACLs (NACLs) do not support security group IDs as sources or destinations. NACLs are stateless, subnet-level firewalls that operate strictly on IP address ranges (CIDRs) and port numbers. They lack the capability to interpret or reference security group identifiers, which are a feature exclusive to stateful security groups operating at the instance level. Therefore, this configuration is syntactically and functionally invalid for NACLs.

  • ✓

    Configure the EC2 instance security group to allow traffic from the ALB security group.

    Why this is correct

    Configuring the EC2 instance security group to allow traffic from the ALB security group is the correct and most robust solution. By referencing the ALB's security group ID as the source in the EC2 instance's inbound rules, you dynamically permit traffic only from the network interfaces associated with that specific ALB. This ensures secure communication, automatically adapts to ALB scaling or underlying IP address changes, and adheres to the principle of least privilege by restricting access solely to the load balancer.

  • ✗

    Configure the EC2 instance security group to allow HTTP traffic from 0.0.0.0/0.

    Why it's wrong here

    Configuring the EC2 instance security group to allow HTTP traffic from 0.0.0.0/0 would permit inbound connections from any IP address on the internet or within the VPC. While this would technically allow the ALB to reach the instances, it severely compromises security by exposing the backend instances directly to a much broader network, bypassing the intended security layer provided by the ALB. This violates the principle of least privilege and creates an unnecessary, significant attack surface, making the instances vulnerable to unauthorized access.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.