QuestionQ41

Infrastructure Security

A company is deploying a new application in a new AWS account. A VPC and subnets have been created for the application. The application VPC has been peered with an existing VPC in another account in the same AWS Region to access databases. Amazon EC2 instances will be regularly created and terminated in the application VPC, but only some will require database access in the peered VPC over TCP port 1521. A security engineer must ensure that only the EC2 instances requiring database access can reach the databases through the network.

How should the security engineer implement this solution?

Explanation

A security group rule in a same-Region peered VPC can reference a security group in the peer VPC, including one owned by another AWS account. Allowing TCP port 1521 inbound on the database security group from an application security group restricts access to only the instances associated with that application group, so newly created instances receive access only when explicitly assigned the group. Security groups are stateful, so return traffic is automatically allowed. Update your security groups to reference peer security groups

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!