Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company has a security group that allows inbound SSH from 0.0.0.0/0. The security team wants to restrict access to only the company's public IP range 203.0.113.0/24. What change should be made?

⚠ Common exam trap

It's easy for candidates to confuse the stateless behavior of network ACLs with the stateful behavior of security groups, leading them to incorrectly believe that adding a deny rule in a network ACL can override a security group's allow rule for the same traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the inbound SSH rule in the security group to source 203.0.113.0/24.

Security groups are stateful and act as a virtual firewall for instances. To restrict inbound SSH access from 0.0.0.0/0 to only the company's public IP range, you must modify the existing inbound rule's source CIDR from 0.0.0.0/0 to 203.0.113.0/24. This change directly updates the allowed source IP range, and since security groups evaluate all rules before making a decision, the more specific allowed range will take effect without needing additional rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a network ACL rule to deny SSH from 0.0.0.0/0.

    Why it's wrong here

    A network ACL (NACL) is a stateless, subnet-level filter that is evaluated before the instance's security group. Adding a deny rule for SSH from 0.0.0.0/0 would drop all inbound SSH traffic at the subnet boundary, including from the company's 203.0.113.0/24 range, so it is over-broad rather than restrictive. Because the security group still has its original allow-all rule, you would only be layering a blanket block on top, not limiting access to the intended CIDR.

  • ✓

    Modify the inbound SSH rule in the security group to source 203.0.113.0/24.

    Why this is correct

    Modifying the inbound SSH rule's source from 0.0.0.0/0 to 203.0.113.0/24 is the precise fix because security groups are stateful and support only allow rules. Every IP outside that CIDR will be implicitly denied by the security group's default-deny behavior, while the company's addresses remain permitted. This change directly aligns the security group with the requirement and requires no extra outbound rule because stateful filtering automatically allows the return traffic.

  • ✗

    Add a network ACL rule to allow SSH from 203.0.113.0/24.

    Why it's wrong here

    Adding a NACL allow rule for 203.0.113.0/24 does not alter the security group, which still permits SSH from 0.0.0.0/0. In a default VPC, the existing NACL already has an allow-all rule, so the new rule is simply redundant and has no restrictive effect; in a custom NACL you would also need to remove broader allows. The security group remains the vulnerable, overly permissive control, so this is not a correct fix.

  • ✗

    Remove the inbound SSH rule from the security group.

    Why it's wrong here

    Removing the inbound SSH rule entirely would not restrict access; it would eliminate SSH for everyone, including the 203.0.113.0/24 administrators. Security groups have no explicit deny rules, and an absent inbound allow means no source can initiate SSH traffic. This would likely cause an administrative lockout and is a complete block rather than a targeted restriction to the company IP range.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.