How to Prevent SQL Injection on an EC2 App Behind an NLB on AWS?

A company has an internal web-based application that employees use. The company hosts the application over a VPN in the company’s on-premises network. The application runs on a fleet of Amazon EC2 instances in a private subnet behind a Network Load Balancer (NLB) in the same subnet. The instances are in an Amazon EC2 Auto Scaling group. During a recent security incident, SQL injection occurred on the application. A network engineer must implement a solution to prevent SQL injection attacks in the future. Which combination of steps will meet these requirements? (Choose three.)

  1. Create an AWS WAF web ACL that includes rules to block SQL injection attacks. Source Reference Answer
  2. Create an Amazon CloudFront distribution. Specify the EC2 instances as the origin.
  3. Replace the NLB with an Application Load Balancer. Source Reference Answer
  4. Associate the AWS WAF web ACL with the NLB.
  5. Associate the AWS WAF web ACL with the Application Load Balancer. Source Reference Answer

Community Votes

ACE
100%

100% of anonymous learners picked answer ACE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests that AWS WAF is a Layer 7 protection and can only be associated with an ALB (or CloudFront/API Gateway), not an NLB; the key is to swap NLB for ALB and attach the WAF web ACL to it, while avoiding CloudFront as a mandatory component.

To stop SQL injection on an internal application behind a Network Load Balancer, replace the NLB with an Application Load Balancer and associate an AWS WAF web ACL containing SQL injection rules. The community agrees that WAF cannot be attached to an NLB, making CloudFront unnecessary for this internal VPN-hosted app.

The most common mistake is choosing D, associating the AWS WAF web ACL with the NLB, because WAF cannot protect a Layer 4 NLB and AWS does not support this integration; candidates must replace the NLB with an ALB first.

Community Discussion (5 comments)

woorkim 👍 1 Selected: ACE
While CloudFront can be used as a content delivery network (CDN), it is not necessary in this case. CloudFront is typically used to distribute content to end users with low latency, but it is not required to protect against SQL injection attacks if AWS WAF is applied directly to the ALB.
AlohaEva 👍 3 Selected: ACE
NLB is a Layer 3/4 component WAF is a Layer 7 protection component WAF is not capable of acting on the content of not terminated TLS session (encrypted data) WAF is only available for ALB. So, consider changing NLB to ALB and use WAF with ALB
cas_tori 👍 1 Selected: ACE
this is ACE
aragon_saa 👍 1
Answer is ACE
Cacheirez 👍 3 Selected: ACE
AWS WAF (Web Application Firewall) can help protect your application from common web exploits, including SQL injection. By creating a web ACL (Access Control List) with rules specifically designed to detect and block SQL injection attempts, you can add a layer of protection to your application. AWS WAF can only be associated with an Application Load Balancer (ALB), not a Network Load Balancer (NLB). Replacing the NLB with an ALB is necessary to enable WAF protection for your web application. Once the ALB is in place, you can associate the AWS WAF web ACL with the ALB. This ensures that incoming traffic is inspected by the WAF rules, providing protection against SQL injection attacks.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A is correct because AWS WAF can inspect HTTP/HTTPS requests and block SQL injection using managed rules or custom rules. C is correct because the existing NLB is a Layer 4 load balancer and cannot be associated with AWS WAF, so it must be replaced with an Application Load Balancer. E is correct because the WAF web ACL must be attached to the ALB to filter requests before they reach the application. Together, A, C, and E provide the required SQL injection protection without adding unnecessary components.

Why the Other Options Are Wrong

B is wrong because CloudFront is a content delivery network and is not required for an internal VPN-hosted application; it also cannot reach private EC2 instances behind an NLB without additional configuration, and it would not directly prevent SQL injection. D is wrong because AWS WAF web ACLs cannot be associated with a Network Load Balancer — NLB operates at Layer 4 and cannot inspect application-layer payloads, so the WAF would not have visibility into the SQL injection attempts. The only valid way to combine WAF with a load balancer in this scenario is to use an ALB.

Community Comment Notes

Comment [1] correctly observes that NLB is a Layer 3/4 component while WAF is a Layer 7 protection, and WAF cannot act on encrypted TLS traffic unless it is terminated at an ALB; the same comment notes WAF is only available for ALB. Comment [2] reinforces that AWS WAF can only be associated with an Application Load Balancer, not an NLB, and recommends creating a web ACL with SQL injection rules. Comment [3] adds that CloudFront can be used as a CDN but is not necessary when WAF is applied directly to the ALB, supporting the ACE answer.

Official Reference

Exam Strategy

On ANS-C01, remember that AWS WAF requires a Layer 7 resource such as ALB, CloudFront, API Gateway, or App Runner. If the architecture includes an NLB, watch for the step that replaces it with an ALB before associating the WAF web ACL.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide