Enabling an EC2 transparent proxy by disabling source/destination checks

Answer Correct answer: A — Disable source/destination checks on the proxy EC2 instances so they can forward routed traffic; a gateway instance requires this check disabled.

A company has implemented a new security requirement. According to the new requirement, the company must scan all traffic from corporate AWS instances in the company's VPC for violations of the company's security policies. As a result of these scans, the company can block access to and from specific IP addresses. To meet the new requirement, the company deploys a set of Amazon EC2 instances in private subnets to serve as transparent proxies. The company installs approved proxy server software on these EC2 instances. The company modifies the route tables on all subnets to use the corresponding EC2 instances with proxy software as the default route. The company also creates security groups that are compliant with the security policies and assigns these security groups to the EC2 instances. Despite these configurations, the traffic of the EC2 instances in their private subnets is not being properly forwarded to the internet. What should a solutions architect do to resolve this issue?

  1. Disable source/destination checks on the EC2 instances that run the proxy software. Correct Answer
  2. Add a rule to the security group that is assigned to the proxy EC2 instances to allow all traffic between instances that have this security group. Assign this security group to all EC2 instances in the VPC.
  3. Change the VPCs DHCP options set. Set the DNS server options to point to the addresses of the proxy EC2 instances.
  4. Assign one additional elastic network interface to each proxy EC2 instance. Ensure that one of these network interfaces has a route to the private subnets. Ensure that the other network interface has a route to the internet.

Community Votes

A
75%
D
25%

75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Any EC2 instance that routes or forwards traffic for other instances must have source/destination checking disabled, otherwise the VPC discards packets not originating from or destined to the instance itself.

An EC2 instance deployed as a transparent proxy in a private subnet is configured as the default route but does not forward traffic. Because an instance acting as a network gateway must have source/destination checks disabled, that is the missing configuration.

Assuming the issue is security-group or DHCP/DNS configuration (Options B/C) — those do not address the fact that the instance, as a router, is dropping forwarded packets.

Community Discussion (9 comments)

kejam 👍 9 Selected: A
Answer A: Proxies like NATs will need SrcDestCheck disabled https://docs.aws.amazon.com/vpc/latest/userguide/VPC_NAT_Instance.html#EIP_Disable_SrcDestCheck
0b43291 👍 1 Selected: A
In an Amazon VPC, the source/destination check is a security feature that ensures that an instance cannot be used as a network gateway or router to forward traffic between resources. By default, this check is enabled on all EC2 instances. When you want to use an EC2 instance as a transparent proxy or network appliance to forward traffic between resources, you need to disable the source/destination check on that instance. This allows the instance to receive and forward traffic that is not destined for itself. The other options provided would not resolve the issue: Option B (adding a security group rule) would not enable the proxy instances to forward traffic, as the source/destination check is a separate network configuration. Option C (changing DHCP options) would not affect the ability of the proxy instances to forward traffic. Option D (adding additional network interfaces) is not necessary, as the issue is related to the source/destination check and not the network interface configuration.
AzureDP900 👍 1
Option A resolves the issue by allowing the traffic of the EC2 instances in their private subnets to be properly forwarded to the internet.
chris_spencer 👍 1
With A i am missing the route to the internet via a NAT Gateway or NAT Instance via a ENI, with D i miss the scr/dst check
ahrentom 👍 2 Selected: D
"the company deploys a set of Amazon EC2 instances in private subnets to serve as transparent proxies." How could a Proxy in a private Subnet communicate with the Internet? So we need a second network card with connection to an IGW. Anwser D
Russs99 👍 2 Selected: D
While disabling security checks might seem like a solution, it's not recommended for production environments as it weakens security. The issue lies in routing, not security
TheCloudGuruu 👍 1 Selected: A
Answer is A, proxy
HunkyBunky 👍 1 Selected: A
Answer is - A
alexis123456 👍 3
Correct Answer is A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A disables source/destination checks on the proxy instances. By default, EC2 checks that an instance is the source or destination of any traffic it sends or receives; a transparent proxy forwards traffic for other hosts, so this check must be turned off for the proxy to work.

Why the Other Options Are Wrong

Option B changes security groups but does not allow the instance to forward transit traffic. Option C alters DNS resolution, irrelevant to packet forwarding. Option D adds an ENI but still leaves source/destination checks enabled, so forwarding would still fail.

Community Comment Notes

kejam (likes 9) states proxies like NATs need source/destination checks disabled and links the VPC NAT instance documentation. The vote is A (75) over D (25), though some debated whether an internet route also exists (presumably already configured via NAT/IGW).

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide