Restrict the RDS subnet NACL to PostgreSQL 5432 from the app subnet with ephemeral outbound
A company operates a web application that runs on Amazon EC2 instances. The application listens on port 80 and port 443. The company uses an Application Load Balancer (ALB) with AWS WAF to terminate SSL and to forward traffic to the application instances only on port 80. The ALB is in public subnets that are associated with a network ACL that is named NACL1. The application instances are in dedicated private subnets that are associated with a network ACL that is named NACL2. An Amazon RDS for PostgreSQL DB instance that uses port 5432 is in a dedicated private subnet that is associated with a network ACL that is named NACL3. All the network ACLs currently allow all inbound and outbound traffic. Which set of network ACL changes will increase the security of the application while ensuring functionality?
Community Votes
75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
NACL rules use CIDR ranges, not other NACL identifiers as sources, so a correct rule references the application subnet's CIDR. The RDS instance only needs PostgreSQL 5432 from the app tier; restricting NACL3 to that plus ephemeral outbound for replies hardens the data tier without breaking the ALB→EC2 flow that security groups already govern.
A web tier (ALB/WAF on 80/443 → EC2 on 80) fronts an RDS for PostgreSQL (5432) in dedicated private subnets, and all NACLs currently allow all traffic. The security gain comes from tightening the database subnet NACL (NACL3): allow inbound 5432 only from the application-subnet CIDR and allow outbound to the application subnet on ephemeral ports (1024–65535) for DB responses, while leaving the already-sufficient ALB-to-EC2 path alone.
Referencing another NACL (e.g., NACL2) as a source in a rule—NACL rules require IP CIDRs, so such a rule is invalid. Or modifying the application subnet NACL (NACL2) when the ALB already forwards to port 80 on the instances via security groups and the default allow-all there is sufficient.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.