Enabling an EC2 transparent proxy by disabling source/destination checks
A company has implemented a new security requirement. According to the new requirement, the company must scan all traffic from corporate AWS instances in the company's VPC for violations of the company's security policies. As a result of these scans, the company can block access to and from specific IP addresses. To meet the new requirement, the company deploys a set of Amazon EC2 instances in private subnets to serve as transparent proxies. The company installs approved proxy server software on these EC2 instances. The company modifies the route tables on all subnets to use the corresponding EC2 instances with proxy software as the default route. The company also creates security groups that are compliant with the security policies and assigns these security groups to the EC2 instances. Despite these configurations, the traffic of the EC2 instances in their private subnets is not being properly forwarded to the internet. What should a solutions architect do to resolve this issue?
Community Votes
75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Any EC2 instance that routes or forwards traffic for other instances must have source/destination checking disabled, otherwise the VPC discards packets not originating from or destined to the instance itself.
An EC2 instance deployed as a transparent proxy in a private subnet is configured as the default route but does not forward traffic. Because an instance acting as a network gateway must have source/destination checks disabled, that is the missing configuration.
Assuming the issue is security-group or DHCP/DNS configuration (Options B/C) — those do not address the fact that the instance, as a router, is dropping forwarded packets.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A disables source/destination checks on the proxy instances. By default, EC2 checks that an instance is the source or destination of any traffic it sends or receives; a transparent proxy forwards traffic for other hosts, so this check must be turned off for the proxy to work.Why the Other Options Are Wrong
Option B changes security groups but does not allow the instance to forward transit traffic. Option C alters DNS resolution, irrelevant to packet forwarding. Option D adds an ENI but still leaves source/destination checks enabled, so forwarding would still fail.Community Comment Notes
kejam (likes 9) states proxies like NATs need source/destination checks disabled and links the VPC NAT instance documentation. The vote is A (75) over D (25), though some debated whether an internet route also exists (presumably already configured via NAT/IGW).Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →