Securing workloads and applications
Task statement 1.2 is about securing the application itself: controlling network traffic, keeping tiers private, giving applications credentials safely and protecting databases. This chapter pulls those threads together.
Security groups vs network ACLs
| Security group | Network ACL (NACL) | |
|---|---|---|
| Applies to | Network interfaces (instances, load balancers, RDS…) | Subnets |
| Rules | Allow only | Allow and deny |
| State | Stateful — return traffic automatically allowed | Stateless — return traffic must be allowed explicitly (ephemeral ports) |
| Evaluation | All rules evaluated | Rules evaluated in number order, first match wins |
| Default | New SG: deny all inbound, allow all outbound | Default NACL: allow all; custom NACL: deny all |
| Can reference | Other security groups | Only CIDR ranges |
Use security groups as the main control, referencing each other between tiers ("app SG allows port 8080 from ALB SG"). Use NACLs for coarse subnet-level rules — especially to explicitly block an IP range, which security groups can't do.
Network segmentation
A classic three-tier design:
| Tier | Subnet | Inbound allowed from |
|---|---|---|
| Load balancer | Public subnets in 2+ AZs | Internet on 443 |
| Application | Private subnets | Load balancer security group only |
| Database | Private (isolated) subnets | Application security group only, on the DB port |
- Private instances reach the internet for updates through a NAT gateway in a public subnet.
- Nothing in the database tier needs a route to the internet at all.
Admin access without exposing servers
| Option | Security |
|---|---|
| SSH/RDP from the internet to every server | ✗ Avoid |
| Bastion host in a public subnet, restricted to company IPs | Acceptable, but another server to patch |
| AWS Systems Manager Session Manager | ✓ Best: no inbound ports, no bastion, no SSH keys; IAM-controlled and logged |
| EC2 Instance Connect (including Endpoint for private instances) | ✓ Short-lived keys, IAM-controlled |
Private access to AWS services
By default, an instance in a private subnet calls S3 or DynamoDB through a NAT gateway and the public internet. VPC endpoints keep this traffic on the AWS network:
- Gateway endpoints for S3 and DynamoDB — free; added as route table targets.
- Interface endpoints (AWS PrivateLink) for most other services — private IPs in your subnets; hourly and data charges.
- Endpoint policies restrict what can be accessed through the endpoint; bucket policies can require access via a specific endpoint (
aws:SourceVpce).
Cue: "access S3 from private subnets without traversing the internet" → gateway VPC endpoint. Covered fully in VPC connectivity.
Application credentials and configuration
- Give compute an IAM role, never embedded keys.
- Store secrets in Secrets Manager (with rotation) or Parameter Store; fetch at runtime.
- Use IMDSv2 on EC2 to protect instance metadata (and the role credentials it exposes) from SSRF-style attacks.
Securing databases
| Control | How |
|---|---|
| Network | Private subnets; security group allowing only the app tier |
| Authentication | Database users; IAM database authentication for RDS/Aurora MySQL and PostgreSQL (short-lived tokens instead of passwords) |
| Credentials | Secrets Manager with automatic rotation |
| Encryption at rest | KMS, enabled at creation |
| Encryption in transit | Require TLS connections |
| Connection management | RDS Proxy — pools connections, can enforce IAM auth and uses Secrets Manager |
| Auditing | Database audit logs to CloudWatch Logs; CloudTrail for API actions |
Securing external connections
- AWS Site-to-Site VPN — encrypted IPsec tunnels over the internet between your network and AWS.
- AWS Client VPN — managed OpenVPN-based access for remote users.
- AWS Direct Connect — private, dedicated connection; add VPN or MACsec when encryption is required.
Exam patterns
- "Block a specific malicious IP range from a subnet" → NACL deny rule.
- "Allow the database to accept connections only from the application servers" → DB security group referencing the app security group.
- "Administer private instances without opening ports or managing keys" → Session Manager.
- "Lambda must connect to RDS without exhausting connections" → RDS Proxy.