Courseiva
Security and Compliance →mediumMultiple Select

DOP-C02 Security and Compliance Practice Question

Which TWO actions should a DevOps engineer take to secure a web application running on EC2 instances behind an Application Load Balancer? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS WAF on the ALB to filter malicious requests.

Correct answers are D and E. Option D: AWS WAF on the ALB helps filter out common web exploits. Option E: Configuring the EC2 security group to allow inbound traffic only from the ALB's security group ensures that direct access to instances is blocked, forcing traffic through the ALB. Option A is incorrect because allowing all inbound traffic (0.0.0.0/0) on port 443 exposes instances directly to the internet, bypassing the ALB. Option B is incorrect: network ACLs are stateless and less granular than security groups; using a NACL to allow traffic from the ALB's subnet is not a recommended practice for instance-level security. Option C is incorrect: placing EC2 instances behind CloudFront is a content delivery optimization, not a security measure to protect the application layer; it does not replace the need for WAF or security group restrictions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the EC2 instance security group to allow inbound traffic from 0.0.0.0/0 on port 443.

    Why it's wrong here

    Opening port 443 to 0.0.0.0/0 on the EC2 instances' security group permits direct, unmediated access to the web servers, completely bypassing the Application Load Balancer. This defeats the purpose of placing the ALB in front of the workloads because requests never traverse the ALB, so AWS WAF rules, connection draining, and other ALB-level protections are not applied. It also dramatically expands the attack surface by exposing the instances' public IPs to the internet, rather than restricting ingress to the ALB's security group.

  • ✗

    Use a network ACL to allow inbound HTTP/S traffic only from the ALB's subnet.

    Why it's wrong here

    Network ACLs are stateless and operate at the subnet boundary, not at the instance level, so they lack the fine-grained, stateful filtering that security groups provide. Even if you restrict inbound HTTP/S to the ALB's subnet CIDR, the instances would still need NACL rules for ephemeral return ports, and any other resource in that subnet with the right source IP could reach the instances. The recommended practice is to use security group-to-security group references—specifically, allowing ingress only from the ALB's security group—which scales with dynamic IP addresses and provides instance-level stateful enforcement.

  • ✗

    Place the EC2 instances behind an Amazon CloudFront distribution.

    Why it's wrong here

    CloudFront is a content delivery network and does not directly replace the ALB for security. It can be used in front of the ALB for additional DDoS protection, but it is not a required security action for the described setup.

  • ✓

    Enable AWS WAF on the ALB to filter malicious requests.

    Why this is correct

    Attaching AWS WAF to the Application Load Balancer adds a managed Layer 7 firewall that filters incoming HTTP(S) requests before they reach the target group. WAF can block common web exploits such as SQL injection, cross-site scripting (XSS), and excessive request patterns via rate-based rules, and it integrates with AWS Managed Rules for OWASP Top 10 protection. This is a required security action for a publicly exposed web workload because security groups alone only control transport-level access and cannot inspect payloads, and it can be used alongside AWS Shield for DDoS mitigation.

  • ✓

    Configure the EC2 instance security group to allow inbound traffic only from the ALB's security group.

    Why this is correct

    Configuring the EC2 instance security group to reference the ALB's security group as the source explicitly permits traffic only from the ALB's elastic network interfaces, even as the ALB scales and its IP addresses change. This prevents clients from reaching the instances directly over the internet and guarantees that all incoming traffic has passed through the ALB, where WAF and TLS termination are enforced. It is a fundamental security group best practice for private instances behind a load balancer, rather than relying on subnet-level NACLs or CIDR ranges.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.