SCS-C02 Infrastructure Security Practice Question
A company has a security group rule that allows inbound traffic from 0.0.0.0/0 on port 22. The security engineer wants to restrict SSH access to only the company's public IP range (203.0.113.0/24). What is the correct way to update the security group rule?
⚠ Common exam trap
The trap here is assuming that adding a new rule with a narrower CIDR will override the existing broader rule, but security groups are allow-only and all rules are evaluated together, so the broader rule must be removed or modified.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24.
Modifying the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24 directly restricts SSH access to the company's public IP range. Security groups are stateful and allow you to edit rules in place, so this is the simplest and most accurate method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the existing inbound rule and do not add any new rule; SSH access will be denied by default.
Why it's wrong here
Removing the existing inbound rule and adding no replacement would cause the security group to evaluate no inbound allow rules for SSH, so all inbound SSH traffic would be implicitly denied. While this does eliminate the 0.0.0.0/0 exposure, it also blocks the company's valid 203.0.113.0/24 administrators, breaking legitimate access. The requirement is to restrict the source, not to remove SSH access entirely, so this is an overly destructive action.
- ✓
Modify the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24.
Why this is correct
Modifying the existing rule's source CIDR from 0.0.0.0/0 to 203.0.113.0/24 is the minimal, precise change: the rule continues to allow TCP/22 only from the company's IP range. Security group rules are stateful and evaluated as a union, so editing the existing rule ensures no separate overly permissive rule remains. This directly satisfies the requirement to allow SSH only from the company IP while preserving connectivity for authorized administrators.
- ✗
Add a new inbound rule with source 203.0.113.0/24 and the security group will automatically deny all other traffic.
Why it's wrong here
Adding a new inbound rule for 203.0.113.0/24 does not revoke the existing 0.0.0.0/0 rule because security groups are permissive: all rules are evaluated, and if any rule matches, traffic is allowed. The overly broad rule remains in force, so SSH from the internet would still be accepted. You must modify or delete the 0.0.0.0/0 rule to actually restrict inbound SSH traffic to the intended source.
- ✗
Change the outbound rules to restrict traffic.
Why it's wrong here
Changing outbound rules cannot restrict inbound SSH traffic because security groups are stateful, and the inbound path is governed solely by the inbound rules. Outbound rules control traffic leaving the instance, not connections arriving on TCP/22. Even a default-deny outbound policy would not prevent an external client from initiating an inbound SSH connection to the instance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.