How to Prevent SQL Injection on an EC2 App Behind an NLB on AWS?
A company has an internal web-based application that employees use. The company hosts the application over a VPN in the company’s on-premises network. The application runs on a fleet of Amazon EC2 instances in a private subnet behind a Network Load Balancer (NLB) in the same subnet. The instances are in an Amazon EC2 Auto Scaling group. During a recent security incident, SQL injection occurred on the application. A network engineer must implement a solution to prevent SQL injection attacks in the future. Which combination of steps will meet these requirements? (Choose three.)
Community Votes
100% of anonymous learners picked answer ACE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests that AWS WAF is a Layer 7 protection and can only be associated with an ALB (or CloudFront/API Gateway), not an NLB; the key is to swap NLB for ALB and attach the WAF web ACL to it, while avoiding CloudFront as a mandatory component.
To stop SQL injection on an internal application behind a Network Load Balancer, replace the NLB with an Application Load Balancer and associate an AWS WAF web ACL containing SQL injection rules. The community agrees that WAF cannot be attached to an NLB, making CloudFront unnecessary for this internal VPN-hosted app.
The most common mistake is choosing D, associating the AWS WAF web ACL with the NLB, because WAF cannot protect a Layer 4 NLB and AWS does not support this integration; candidates must replace the NLB with an ALB first.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A is correct because AWS WAF can inspect HTTP/HTTPS requests and block SQL injection using managed rules or custom rules. C is correct because the existing NLB is a Layer 4 load balancer and cannot be associated with AWS WAF, so it must be replaced with an Application Load Balancer. E is correct because the WAF web ACL must be attached to the ALB to filter requests before they reach the application. Together, A, C, and E provide the required SQL injection protection without adding unnecessary components.
Why the Other Options Are Wrong
B is wrong because CloudFront is a content delivery network and is not required for an internal VPN-hosted application; it also cannot reach private EC2 instances behind an NLB without additional configuration, and it would not directly prevent SQL injection. D is wrong because AWS WAF web ACLs cannot be associated with a Network Load Balancer — NLB operates at Layer 4 and cannot inspect application-layer payloads, so the WAF would not have visibility into the SQL injection attempts. The only valid way to combine WAF with a load balancer in this scenario is to use an ALB.
Community Comment Notes
Comment [1] correctly observes that NLB is a Layer 3/4 component while WAF is a Layer 7 protection, and WAF cannot act on encrypted TLS traffic unless it is terminated at an ALB; the same comment notes WAF is only available for ALB. Comment [2] reinforces that AWS WAF can only be associated with an Application Load Balancer, not an NLB, and recommends creating a web ACL with SQL injection rules. Comment [3] adds that CloudFront can be used as a CDN but is not necessary when WAF is applied directly to the ALB, supporting the ACE answer.
Official Reference
Exam Strategy
On ANS-C01, remember that AWS WAF requires a Layer 7 resource such as ALB, CloudFront, API Gateway, or App Runner. If the architecture includes an NLB, watch for the step that replaces it with an ALB before associating the WAF web ACL.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →