Verify the security group on the server's ENI and that the instance is registered as an ALB target
A security engineer has been asked to troubleshoot inbound connectivity to a web server. This single web server is not receiving inbound connections from the internet, whereas all other web servers are functioning properly. The architecture includes network ACLs, security groups, and a virtual security appliance. In addition, the development team has implemented Application Load Balancers (ALBs) to distribute the load across all web servers. It is a requirement that traffic between the web servers and the internet flow through the virtual security appliance. The security engineer has verified the following: 1. The rule set in the security groups is correct. 2. The rule set in the network ACLs is correct. 3. The rule set in the virtual appliance is correct. Which of the following are other valid items to troubleshoot in this scenario? (Choose two.)
Community Votes
56% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Since all other servers work and the shared layers (NACL, appliance, SG rules) are verified, the failure is specific to this instance. B checks the SG actually bound to this ENI—an incorrect SG would drop its traffic. D checks ALB target registration—a deregistered instance receives nothing from the ALB. C (route to the appliance) applies to the whole subnet, so it would break all servers, not just one, making it a weaker single-server explanation. B and D are the valid per-instance checks.
One web server receives no inbound internet traffic while the others work, and the SG, NACL, and virtual-appliance rule sets are already confirmed correct. Because it is a single server (not the whole subnet), the cause is per-instance: confirm the correct security group is attached to this server's ENI (a wrong/missing SG would block its traffic) and confirm the instance is actually registered as a target in the ALB target group (if it is deregistered, the ALB will not forward traffic to it).
Focusing only on the route table (C)—it applies to the entire subnet, so if it pointed wrong, all servers would fail, not just this one; it does not explain a single-server outage. Overlooking the ENI's attached SG (B) or ALB target registration (D), which are the instance-specific controls most likely to differ for one server.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.