Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company has a security group rule that allows inbound traffic from 0.0.0.0/0 on port 22. The security engineer wants to restrict SSH access to only the company's public IP range (203.0.113.0/24). What is the correct way to update the security group rule?

⚠ Common exam trap

The trap here is assuming that adding a new rule with a narrower CIDR will override the existing broader rule, but security groups are allow-only and all rules are evaluated together, so the broader rule must be removed or modified.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24.

Modifying the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24 directly restricts SSH access to the company's public IP range. Security groups are stateful and allow you to edit rules in place, so this is the simplest and most accurate method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove the existing inbound rule and do not add any new rule; SSH access will be denied by default.

    Why it's wrong here

    Removing the existing inbound rule and adding no replacement would cause the security group to evaluate no inbound allow rules for SSH, so all inbound SSH traffic would be implicitly denied. While this does eliminate the 0.0.0.0/0 exposure, it also blocks the company's valid 203.0.113.0/24 administrators, breaking legitimate access. The requirement is to restrict the source, not to remove SSH access entirely, so this is an overly destructive action.

  • ✓

    Modify the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24.

    Why this is correct

    Modifying the existing rule's source CIDR from 0.0.0.0/0 to 203.0.113.0/24 is the minimal, precise change: the rule continues to allow TCP/22 only from the company's IP range. Security group rules are stateful and evaluated as a union, so editing the existing rule ensures no separate overly permissive rule remains. This directly satisfies the requirement to allow SSH only from the company IP while preserving connectivity for authorized administrators.

  • ✗

    Add a new inbound rule with source 203.0.113.0/24 and the security group will automatically deny all other traffic.

    Why it's wrong here

    Adding a new inbound rule for 203.0.113.0/24 does not revoke the existing 0.0.0.0/0 rule because security groups are permissive: all rules are evaluated, and if any rule matches, traffic is allowed. The overly broad rule remains in force, so SSH from the internet would still be accepted. You must modify or delete the 0.0.0.0/0 rule to actually restrict inbound SSH traffic to the intended source.

  • ✗

    Change the outbound rules to restrict traffic.

    Why it's wrong here

    Changing outbound rules cannot restrict inbound SSH traffic because security groups are stateful, and the inbound path is governed solely by the inbound rules. Outbound rules control traffic leaving the instance, not connections arriving on TCP/22. Even a default-deny outbound policy would not prevent an external client from initiating an inbound SSH connection to the instance.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.