DOP-C02 Security and Compliance Practice Question
Which TWO actions should a DevOps engineer take to secure a web application running on EC2 instances behind an Application Load Balancer? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS WAF on the ALB to filter malicious requests.
Correct answers are D and E. Option D: AWS WAF on the ALB helps filter out common web exploits. Option E: Configuring the EC2 security group to allow inbound traffic only from the ALB's security group ensures that direct access to instances is blocked, forcing traffic through the ALB. Option A is incorrect because allowing all inbound traffic (0.0.0.0/0) on port 443 exposes instances directly to the internet, bypassing the ALB. Option B is incorrect: network ACLs are stateless and less granular than security groups; using a NACL to allow traffic from the ALB's subnet is not a recommended practice for instance-level security. Option C is incorrect: placing EC2 instances behind CloudFront is a content delivery optimization, not a security measure to protect the application layer; it does not replace the need for WAF or security group restrictions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the EC2 instance security group to allow inbound traffic from 0.0.0.0/0 on port 443.
Why it's wrong here
Opening port 443 to 0.0.0.0/0 on the EC2 instances' security group permits direct, unmediated access to the web servers, completely bypassing the Application Load Balancer. This defeats the purpose of placing the ALB in front of the workloads because requests never traverse the ALB, so AWS WAF rules, connection draining, and other ALB-level protections are not applied. It also dramatically expands the attack surface by exposing the instances' public IPs to the internet, rather than restricting ingress to the ALB's security group.
- ✗
Use a network ACL to allow inbound HTTP/S traffic only from the ALB's subnet.
Why it's wrong here
Network ACLs are stateless and operate at the subnet boundary, not at the instance level, so they lack the fine-grained, stateful filtering that security groups provide. Even if you restrict inbound HTTP/S to the ALB's subnet CIDR, the instances would still need NACL rules for ephemeral return ports, and any other resource in that subnet with the right source IP could reach the instances. The recommended practice is to use security group-to-security group references—specifically, allowing ingress only from the ALB's security group—which scales with dynamic IP addresses and provides instance-level stateful enforcement.
- ✗
Place the EC2 instances behind an Amazon CloudFront distribution.
Why it's wrong here
CloudFront is a content delivery network and does not directly replace the ALB for security. It can be used in front of the ALB for additional DDoS protection, but it is not a required security action for the described setup.
- ✓
Enable AWS WAF on the ALB to filter malicious requests.
Why this is correct
Attaching AWS WAF to the Application Load Balancer adds a managed Layer 7 firewall that filters incoming HTTP(S) requests before they reach the target group. WAF can block common web exploits such as SQL injection, cross-site scripting (XSS), and excessive request patterns via rate-based rules, and it integrates with AWS Managed Rules for OWASP Top 10 protection. This is a required security action for a publicly exposed web workload because security groups alone only control transport-level access and cannot inspect payloads, and it can be used alongside AWS Shield for DDoS mitigation.
- ✓
Configure the EC2 instance security group to allow inbound traffic only from the ALB's security group.
Why this is correct
Configuring the EC2 instance security group to reference the ALB's security group as the source explicitly permits traffic only from the ALB's elastic network interfaces, even as the ALB scales and its IP addresses change. This prevents clients from reaching the instances directly over the internet and guarantees that all incoming traffic has passed through the ALB, where WAF and TLS termination are enforced. It is a fundamental security group best practice for private instances behind a load balancer, rather than relying on subnet-level NACLs or CIDR ranges.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.