Courseiva
Infrastructure Security →hardMultiple Choice

Restrict EC2 Behind ALB to ALB's Security Group

A company runs a web application on Amazon EC2 behind an Application Load Balancer (ALB). The security team wants to allow only traffic from the ALB to reach the EC2 instances. Which security group configuration should be used?

Quick Answer

The correct answer is to allow inbound traffic from the ALB’s security group ID on the EC2 security group. This works because AWS security groups support stateful, rule-based referencing by security group ID rather than by IP address, meaning the EC2 instance’s security group can be configured to accept traffic only from the ALB’s security group as the source. This approach is preferred over using CIDR blocks because the ALB’s IP addresses can change dynamically due to scaling or replacement, making a static IP rule brittle. On the AWS Certified Security Specialty SCS-C02 exam, this question tests your understanding of security group chaining and the principle of least privilege for network traffic. A common trap is assuming you must use the ALB’s IP range or a VPC CIDR, but the exam expects you to recognize that security group IDs are the correct, scalable method. Memory tip: think “group-to-group, not IP-to-group” — if you see a security group ID as a source, you’re on the right track.

⚠ Common exam trap

It's easy for candidates to assume ALBs have fixed private IP addresses and choose Option A, not realizing that ALB IPs are dynamic and that security group referencing is the AWS-recommended method for this pattern.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow inbound traffic from the ALB's security group ID on the EC2 security group.

Security groups can reference other security groups by ID. By setting an inbound rule on the EC2 security group that references the ALB's security group ID, only traffic originating from the ALB is allowed. This is the recommended approach as ALB private IP addresses are dynamic and can change, making IP-based rules (Option A) unreliable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow inbound traffic from the ALB's private IP addresses on the EC2 security group.

    Why it's wrong here

    ALB node IP addresses change as the load balancer scales, so hard-coded addresses break and admit stale nodes. It tempts because it appears to target the ALB specifically, and would suit a static appliance, but referencing the ALB's security group as the source is the mechanism that tracks it.

  • ✗

    Allow inbound traffic from the VPC CIDR block on the EC2 security group.

    Why it's wrong here

    The VPC CIDR permits every resource inside the VPC, including unrelated instances and NAT gateways, not solely the ALB. It tempts because it narrows exposure from the internet, and would suit internal-only tiers, but it fails the requirement that only the ALB's security group reach the instances.

  • ✓

    Allow inbound traffic from the ALB's security group ID on the EC2 security group.

    Why this is correct

    Referencing the ALB's security group ID as the source makes the EC2 rule follow the load balancer automatically, so only traffic from that ALB is permitted. This is more precise than CIDR ranges, which would also admit any host in the ALB's subnets.

  • ✗

    Allow inbound HTTP traffic from 0.0.0.0/0 on the EC2 security group.

    Why it's wrong here

    0.0.0.0/0 admits traffic from any internet source directly to the instances, bypassing the ALB entirely. It tempts as the quick fix for a public web tier, and would suit an instance genuinely serving users directly, but here it defeats the requirement that only the ALB reach the EC2 instances.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company runs a critical application on Amazon EC2 instances behind an Application Load Balancer (ALB). The security team wants to ensure that only traffic from the ALB reaches the EC2 instances, and that instances cannot initiate outbound connections to the internet. Which combination of security group rules should be implemented? (Select TWO.)

hard
  • A.Inbound rule: Allow HTTP/HTTPS from 0.0.0.0/0.
  • ✓ B.Inbound rule: Allow HTTP/HTTPS from the ALB's security group.
  • C.Outbound rule: Allow all traffic to the ALB's security group only.
  • ✓ D.Outbound rule: Deny all traffic to 0.0.0.0/0.
  • E.Outbound rule: Allow all traffic to 0.0.0.0/0.

Why B: Referencing the ALB's security group as the source for inbound HTTP/HTTPS traffic ensures that only traffic that has passed through the ALB can reach the EC2 instances. This leverages security group chaining, where the ALB's security group acts as a trusted source, preventing direct internet access to the instances. Option D is correct because a deny-all outbound rule to 0.0.0.0/0 blocks all outbound internet connections, satisfying the requirement that instances cannot initiate outbound connections.

Variation 2. A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The ALB is configured to terminate SSL/TLS and forward traffic to the instances over HTTP. The security team wants to ensure that the instances only accept traffic from the ALB, not from any other source. How can this be achieved?

hard
  • A.Configure the instance security group to allow HTTP traffic only from the VPC CIDR block.
  • ✓ B.Configure the instance security group to allow HTTP traffic only from the ALB's security group.
  • C.Configure the network ACL on the instance's subnet to allow HTTP traffic only from the ALB's private IP address.
  • D.Configure the instance security group to allow HTTP traffic only from the subnet CIDR block where the ALB resides.

Why B: Referencing the ALB's security group in the instance security group rule allows traffic only from the ALB, regardless of the ALB's IP address changes. This leverages AWS security group referencing, which is a managed and scalable way to restrict traffic to a specific source security group. The ALB's security group acts as a logical identifier, ensuring that only traffic forwarded by the ALB reaches the instances.

Variation 3. A company is deploying a web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The instances are in a private subnet. How should the security group for the EC2 instances be configured?

easy
  • A.Allow inbound HTTP/HTTPS from the internet gateway.
  • ✓ B.Allow inbound HTTP/HTTPS from the security group of the ALB.
  • C.Allow inbound HTTP/HTTPS from 0.0.0.0/0.
  • D.Allow inbound HTTP/HTTPS from the VPC CIDR.

Why B: The EC2 instances are in a private subnet and should only accept traffic from the ALB, not directly from the internet. By referencing the ALB's security group as the source, you ensure that only traffic that has passed through the ALB can reach the instances, maintaining a secure architecture. This follows the principle of least privilege and prevents bypassing the load balancer.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.