AnswerCorrect answer: B — deny inbound 3306 and allow inbound ephemeral (1024-65535) for 443 responses, with outbound 443 allowed; NACLs are stateless.
A public subnet contains two Amazon EC2 instances. The subnet has a custom network ACL. A security engineer is designing a solution to improve the subnet security. The solution must allow outbound traffic to an internet service that uses TLS through port 443. The solution also must deny inbound traffic that is destined for MySQL port 3306. Which network ACL rule set meets these requirements?
Use inbound rule 100 to allow traffic on TCP port 443. Use inbound rule 200 to deny traffic on TCP port 3306. Use outbound rule 100 to allow traffic on TCP port 443.
Use inbound rule 100 to deny traffic on TCP port 3306. Use inbound rule 200 to allow traffic on TCP port range 1024-65535. Use outbound rule 100 to allow traffic on TCP port 443. Correct Answer
Use inbound rule 100 to allow traffic on TCP port range 1024-65535. Use inbound rule 200 to deny traffic on TCP port 3306. Use outbound rule 100 to allow traffic on TCP port 443.
Use inbound rule 100 to deny traffic on TCP port 3306. Use inbound rule 200 to allow traffic on TCP port 443. Use outbound rule 100 to allow traffic on TCP port 443.
Community Votes
D
50%
B
50%
50% of anonymous learners picked answer D.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Stateless NACLs evaluate every packet in both directions, so outbound-initiated 443 needs a matching inbound allow on ephemeral ports for the response. Denying inbound 3306 explicitly (rule 100) blocks MySQL, and allowing inbound 1024–65535 (rule 200) lets 443 responses through. Options that only allow inbound 443 (and not ephemeral) break the return path.
A custom NACL must permit outbound TLS to an internet service on 443 and block inbound MySQL 3306. Because NACLs are stateless, the return traffic for an outbound 443 connection arrives inbound on an ephemeral port (1024–65535), so the inbound rules must deny 3306 and allow the ephemeral range. The correct rule set denies inbound 3306 (rule 100) and allows inbound ephemeral (rule 200), with outbound 443 allowed—satisfying both requirements.
Allowing only inbound 443 and not the ephemeral return range (options A/D): the response to an outbound 443 request comes back on a high port, which those rules never permit, so outbound 443 effectively fails. Forgetting that NACLs are stateless and need explicit bidirectional rules.
Community Discussion (5 comments)
slydie👍 2Selected: B
ephemeral ports!
Wardove👍 3Selected: B
Answer is B you need to accept ephemeral range for your tcp response to flow back 443 <-> 1000-65535 example custom network acl https://docs.aws.amazon.com/vpc/latest/userguide/custom-network-acl.html
TareDHakim👍 1Selected: C
Responses to requests sent to port 443 will use ephemeral ports (1024–65535). As for option C, allowing inbound traffic on ephemeral ports (1024–65535) is in rule 200, which is evaluated after the rule denying MySQL traffic (rule 100), returning traffic will be blocked before being allowed.
Pmktechno👍 2Selected: D
This configuration ensures that: Inbound traffic on MySQL port 3306 is denied. Inbound traffic on TCP port 443 (used for TLS) is allowed. Outbound traffic on TCP port 443 is allowed. This setup improves the subnet security by restricting unwanted inbound traffic while allowing necessary outbound traffic for internet services using TLS.
Ucy👍 3Selected: D
The correct answer is: D Use inbound rule 100 to deny traffic on TCP port 3306. Use inbound rule 200 to allow traffic on TCP port 443. Use outbound rule 100 to allow traffic on TCP port 443. Explanation: Inbound Rule 100 to deny traffic on TCP port 3306: This rule denies inbound traffic on MySQL’s default port (3306). It ensures that no traffic can reach the EC2 instances on that port from external sources. Inbound Rule 200 to allow traffic on TCP port 443: This rule allows inbound HTTPS (TLS) traffic on port 443, which is required for your application to communicate with an external internet service over HTTPS. Outbound Rule 100 to allow traffic on TCP port 443: This rule allows outbound traffic from the EC2 instances on port 443. It ensures that the EC2 instances can establish outbound connections to the internet over HTTPS. This rule set allows secure internet access for outbound TLS traffic on port 443 while denying inbound MySQL traffic on port 3306, fulfilling both requirements for security.
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
The rule set denies inbound TCP 3306 (blocking MySQL) and allows inbound TCP 1024–65535 (the ephemeral ports used by responses to outbound 443), with outbound 443 allowed. Because NACLs are stateless, the inbound ephemeral allow is required for outbound 443 sessions to complete, while the explicit 3306 deny meets the inbound block requirement.
Why the Other Options Are Wrong
A and D allow only inbound 443 (not ephemeral), so the return traffic for outbound 443 requests—which arrives on high ports—is never permitted and outbound 443 breaks. C allows ephemeral inbound at rule 100 and denies 3306 at rule 200; it also works, but B's explicit deny-3306-first ordering is the cleaner expression. The key failure mode is any option lacking the ephemeral inbound allow, which A and D do.
Community Comment Notes
Community split B (45) and D (45). The technically correct choices are B or C; D is wrong because it allows only inbound 443 and drops the ephemeral return traffic, breaking outbound TLS. B's commenters noted the ephemeral range (1024–65535) is required for the 443 response. B is the correct, stateless-aware rule set.