Question 1 · choose 1
A web server in a public subnet listens on TCP port 443, but clients on the internet time out. For each attempt, the VPC flow logs of the server's network interface show an ACCEPT record for the inbound packets to port 443 and a REJECT record for the server's response packets to the client's port, such as 51544. The security group allows inbound 443 from anywhere and keeps its default outbound rule. What should the team change?
- AAdd an outbound security group rule that allows TCP 1024-65535 to 0.0.0.0/0
- BAdd an inbound security group rule that allows TCP 1024-65535 from 0.0.0.0/0
- CAdd a 0.0.0.0/0 route to the internet gateway in the subnet's route table
- DAdd an outbound network ACL rule that allows TCP 1024-65535 to 0.0.0.0/0
Show the answer and why
AAdd an outbound security group rule that allows TCP 1024-65535 to 0.0.0.0/0
Incorrect
Security groups are stateful, so responses to allowed inbound traffic are allowed anyway, and the default outbound rule already allows all traffic.
BAdd an inbound security group rule that allows TCP 1024-65535 from 0.0.0.0/0
Incorrect
The inbound request is already accepted. Opening more inbound ports does not let the response leave.
CAdd a 0.0.0.0/0 route to the internet gateway in the subnet's route table
Incorrect
A REJECT record means the traffic was not allowed by a security group or network ACL, not that a route was missing.
DAdd an outbound network ACL rule that allows TCP 1024-65535 to 0.0.0.0/0
Correct
Network ACLs are stateless, so response traffic needs its own rule. Allowed inbound traffic whose response is rejected is the pattern AWS describes for a network ACL that lacks the outbound rule.
ACCEPT in, REJECT out on the same flow points to the stateless layer: the network ACL needs an outbound rule for the clients' ephemeral ports.
AWS documentation