AnswerCorrect answer: D — attach a security group to the ALB that allows only inbound 443, since security groups are allow-only and cannot be overridden by a deny.
A company needs to use HTTPS when connecting to its web applications to meet compliance requirements. These web applications run in Amazon VPC on Amazon EC2 instances behind an Application Load Balancer (ALB). A security engineer wants to ensure that the load balancer will only accept connections over port 443, even if the ALB is mistakenly configured with an HTTP listener. Which configuration steps should the security engineer take to accomplish this task?
Create a security group with a rule that denies inbound connections from 0.0.0.0/0 on port 80. Attach this security group to the ALB to overwrite more permissive rules from the ALB’s default security group.
Create a network ACL that denies inbound connections from 0.0.0.0/0 on port 80. Associate the network ACL with the VPC’s internet gateway.
Create a network ACL that allows outbound connections to the VPC IP range on port 443 only. Associate the network ACL with the VPC’s internet gateway.
Create a security group with a single inbound rule that allows connections from 0.0.0.0/0 on port 443. Ensure this security group is the only one associated with the ALB. Correct Answer
Community Votes
D
80%
A
20%
80% of anonymous learners picked answer D.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Security groups have only allow rules—there is no deny—so an SG that permits only 443 (D) ensures 80 is never allowed at the network layer, satisfying the requirement even if an HTTP listener exists. A's 'deny rule' SG is invalid (SGs cannot deny). B/C attach NACLs to the IGW, but NACLs associate with subnets, not IGWs, and are the wrong mechanism here. D is correct.
To guarantee an ALB accepts only HTTPS (443) even if someone adds an HTTP (80) listener, associate a security group whose only inbound rule allows 443 from 0.0.0.0/0 and make it the sole SG on the ALB. Because security groups are stateful allow-only (no deny rules), allowing only 443 means port 80 traffic is simply not permitted, regardless of any listener.
Creating an SG with a deny rule (A)—security groups are allow-only and have no deny rules, so this is impossible. Associating a NACL with the internet gateway (B/C)—NACLs attach to subnets, not IGWs, and are not the right control for ALB listener restriction. The allow-only SG permitting only 443 (D) is the working approach.
Community Discussion (4 comments)
m_ch333👍 1Selected: D
D. For security group, you can specify allow rules, but not deny rules. https://docs.aws.amazon.com/vpc/latest/userguide/security-group-rules.html
Curl8012👍 2Selected: D
Between A and D, A - There is nothing such as Deny rule in security group D - Although not exhaustive, the best choice among these
IPLogic👍 1Selected: A
Option A is the most effective solution to ensure that the ALB only accepts HTTPS connections. By creating a security group that denies inbound connections on port 80 and attaching it to the ALB, you can override any permissive rules from the default security group. This will prevent HTTP traffic from reaching the ALB, even if it's misconfigured.
jdx000👍 1Selected: D
Agree, D.
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
Security groups are stateful and contain only allow rules—there is no such thing as a deny rule. By attaching a security group to the ALB that has a single inbound allow on port 443 and making it the only SG on the ALB, port 80 traffic is never permitted at the network layer, so even a mistakenly added HTTP listener cannot receive connections. This meets the requirement robustly.
Why the Other Options Are Wrong
A proposes an SG deny rule, which cannot exist—security groups are allow-only. B and C attach a NACL to the internet gateway, but NACLs associate with subnets, not IGWs, and are not how you restrict an ALB's listeners. D is the correct allow-only SG approach.
Community Comment Notes
Community voted D (80), with A a 20 minority. Commenters clarified security groups have no deny rules and that an SG allowing only 443 (and being the only one on the ALB) is the effective control. D confirmed.