Restrict the RDS subnet NACL to PostgreSQL 5432 from the app subnet with ephemeral outbound

Answer Correct answer: B — lock NACL3 to PostgreSQL 5432 inbound from the app subnet CIDR with ephemeral outbound, leaving the app subnet alone.

A company operates a web application that runs on Amazon EC2 instances. The application listens on port 80 and port 443. The company uses an Application Load Balancer (ALB) with AWS WAF to terminate SSL and to forward traffic to the application instances only on port 80. The ALB is in public subnets that are associated with a network ACL that is named NACL1. The application instances are in dedicated private subnets that are associated with a network ACL that is named NACL2. An Amazon RDS for PostgreSQL DB instance that uses port 5432 is in a dedicated private subnet that is associated with a network ACL that is named NACL3. All the network ACLs currently allow all inbound and outbound traffic. Which set of network ACL changes will increase the security of the application while ensuring functionality?

  1. Make the following changes to NACL3:
  2. Make the following changes to NACL3: Correct Answer
  3. Make the following changes to NACL2:
  4. Make the following changes to NACL2:

Community Votes

B
75%
C
25%

75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

NACL rules use CIDR ranges, not other NACL identifiers as sources, so a correct rule references the application subnet's CIDR. The RDS instance only needs PostgreSQL 5432 from the app tier; restricting NACL3 to that plus ephemeral outbound for replies hardens the data tier without breaking the ALB→EC2 flow that security groups already govern.

A web tier (ALB/WAF on 80/443 → EC2 on 80) fronts an RDS for PostgreSQL (5432) in dedicated private subnets, and all NACLs currently allow all traffic. The security gain comes from tightening the database subnet NACL (NACL3): allow inbound 5432 only from the application-subnet CIDR and allow outbound to the application subnet on ephemeral ports (1024–65535) for DB responses, while leaving the already-sufficient ALB-to-EC2 path alone.

Referencing another NACL (e.g., NACL2) as a source in a rule—NACL rules require IP CIDRs, so such a rule is invalid. Or modifying the application subnet NACL (NACL2) when the ALB already forwards to port 80 on the instances via security groups and the default allow-all there is sufficient.

Community Discussion (5 comments)

molerowan 👍 1 Selected: B
A: Referencing NACL2 (instead of CIDR blocks) is invalid—NACL rules require IP ranges, not ACL identifiers. C/D: Modifying NACL2 (application subnet) is unnecessary here. The ALB already forwards traffic to port 80 on the EC2 instances, which is managed by security groups. NACL2’s default allow-all rules are already sufficient for ALB-to-EC2 traffic.
Pat9595 👍 1 Selected: B
Why is B the Best Choice? Restricts Database Access (RDS - NACL3) The RDS instance only needs to accept traffic from the application instances (NACL2) on port 5432 (PostgreSQL). This prevents unauthorized access from other sources. Ensures Proper Response Traffic Flow PostgreSQL replies on ephemeral ports (1024-65536), so outbound traffic from NACL3 to NACL2 must be allowed for the connection to function. Removes Open Access The default allow-all rules are removed, improving security. Only necessary inbound and outbound traffic is permitted.
youonebe 👍 1 Selected: C
Answer is C. By default, AWS creates NACLs that allow all inbound and outbound traffic. To improve security, it is recommended to restrict access to only necessary traffic. There is no need for DB subnet to open a broad range of ports. Another problem with B is, how would you protect the application server if the NACL rule still allows all traffic? The question asked is to protect the application.
TareDHakim 👍 1 Selected: B
B. database will allow access from/to application subnet only
maciekmacku 👍 2
I think B is correct. Inbound 5432 is allowed and outbound for ephemeral ports. Answer A is wrong as you can't use other NACL as a source.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The database subnet (NACL3) is the highest-value target to lock down. Permitting inbound 5432 only from the application-subnet CIDR and outbound to that subnet on ephemeral ports (for PostgreSQL reply traffic) confines database access to the web tier and blocks lateral or external DB access, increasing security while preserving functionality. NACL rules must cite CIDR ranges, not NACL names.

Why the Other Options Are Wrong

A is wrong because it references NACL2 as a source, which is invalid—NACL rules require IP ranges. C and D modify NACL2 (the application subnet); the ALB already forwards to the instances on port 80 via security groups, so the application-subnet NACL needs no change, and altering it does not address the database exposure. The correct tightening targets the DB subnet.

Community Comment Notes

Community favored B (75 votes). Commenters noted A is invalid (NACL cannot reference another NACL as source) and that C/D unnecessarily touch the application subnet when the ALB-to-EC2 path is already handled by security groups. B restricts the database to the app subnet only.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide