AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company runs a two-tier web app in one VPC. An internet-facing ALB in public subnets listens on TCP 443 and forwards to EC2 instances in private subnets. Security group SG-ALB allows TCP 443 from 0.0.0.0/0. Security group SG-App also allows TCP 443 from 0.0.0.0/0. An audit requires SG-App to accept traffic only from the ALB. What is the most operationally efficient change?
Add an outbound rule to SG-ALB that allows TCP 443 to SG-App and remove the inbound rule from SG-App.
Replace the inbound rule in SG-App to allow TCP 443 from the public subnet CIDR ranges that host the ALB.
Replace the inbound rule in SG-App to allow TCP 443 from the private subnet CIDR ranges that host the ALB's network interfaces.
Replace the inbound rule in SG-App to allow TCP 443 from the security group SG-ALB.
Referencing the ALB's security group as the source of an inbound rule automatically limits traffic to the network interfaces that are currently associated with that security group. This approach scales with the ALB, requires no manual updates when IP addresses or subnets change, and maintains stateful return traffic without additional rules. Specifying subnet CIDR blocks would need updates if the ALB is moved or if new subnets are added, and modifying only outbound rules on SG-ALB does not allow the instances to accept the inbound connection. Therefore, replacing the inbound rule in SG-App to allow TCP 443 from SG-ALB is the correct and least-maintenance solution.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an ALB in AWS?
Open an interactive chat with Bash
Why is referencing a security group in inbound rules more efficient than CIDR-based rules?
Open an interactive chat with Bash
What does 'stateful return traffic' mean in security groups?
Open an interactive chat with Bash
Why is referencing a security group as the source more efficient than using subnet CIDR ranges?
Open an interactive chat with Bash
What does 'stateful return traffic' mean in the context of AWS security groups?
Open an interactive chat with Bash
Why wouldn’t adding an outbound rule to SG-ALB and removing SG-App’s inbound rule work?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .