A financial services company runs a three-tier web application on AWS. The application tier consists of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. A security audit reveals that the application instances are receiving large volumes of unwanted traffic directly from the internet on port 443, bypassing the load balancer. The company wants to ensure that only traffic from the ALB can reach the application instances, while allowing the instances to download software updates from the internet. What should a solutions architect recommend?
Referencing the ALB's security group as the source in the instances' inbound rule ensures only traffic that passed through the load balancer is accepted. Placing instances in private subnets removes direct internet routing, and a NAT gateway provides outbound-only internet access for updates, satisfying both requirements without exposing the instances.
Why this answer
The most secure and operationally sound approach is to use security group referencing so that the instances accept traffic only from the load balancer, and to remove direct internet exposure by placing instances in private subnets. A NAT gateway then allows outbound updates. This combination enforces the traffic path through the ALB while preserving necessary outbound connectivity.
Exam trap
The trap here is assuming that an AWS WAF rule or a network ACL can restrict traffic that reaches instances directly, when only security group referencing combined with private subnets removes the direct path.