A developer needs to access an Amazon RDS database from an EC2 instance within a private subnet. The database must only accept traffic from the instance. Which security configuration is most appropriate?
Referencing the EC2 security group ID is a best practice for internal VPC communication. It ensures that any instance associated with that security group can connect to the database. This approach is highly dynamic, as it automatically handles instance IP changes and maintains a secure, restricted network path.
Why this answer
Configuring the RDS Security Group to allow inbound traffic on the database port exclusively from the security group ID associated with the EC2 instance follows the principle of least privilege. This stateful configuration ensures that only authorized resources can communicate with the database, significantly reducing the attack surface. By referencing the security group ID instead of an IP address, the architecture remains resilient to dynamic IP changes.
Exam trap
Candidates often suggest using the EC2 instance's private IP address in the RDS security group. This is brittle because IP addresses change when instances are stopped or terminated.