QuestionQ42

Infrastructure Security

A public subnet contains two Amazon EC2 instances and uses a custom network ACL. A security engineer is designing a solution to strengthen the subnet’s security.

The solution must permit outbound traffic to an internet service that uses TLS over port 443. The solution must also deny inbound traffic destined for MySQL port 3306.

Which network ACL rule set satisfies these requirements?

Explanation

Amazon VPC network ACLs are stateless: return traffic for an instance-initiated HTTPS connection must be explicitly allowed inbound on the client’s ephemeral ports. Because TCP port 3306 falls within the 1024-65535 range, the deny rule must be evaluated before the broad ephemeral-port allow rule. Network ACLs evaluate the lowest-numbered matching rule first, so an inbound deny on 3306 at rule 100 followed by an inbound allow for 1024-65535 at rule 200, plus outbound TCP 443, satisfies both requirements. AWS Network ACL rules

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!