Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company has a security group that allows inbound SSH from a specific IP range. A security engineer notices that the security group rule is not being applied to a newly launched EC2 instance. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates confuse security group statefulness with network ACL statelessness, or assume that a security group rule applies automatically to all instances in a VPC, when in fact each instance must be explicitly associated with the correct security group at launch.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The new EC2 instance was not launched with the correct security group

The most likely cause is that the new EC2 instance was not launched with the correct security group. Security groups act as virtual firewalls for instances, and an instance can only be associated with security groups at launch time. If the engineer launched the instance without explicitly selecting the security group that allows inbound SSH from the specific IP range, the instance would default to the VPC's default security group, which typically does not have the same custom SSH rule. This is a common operational oversight when automating or manually launching instances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The new EC2 instance was not launched with the correct security group

    Why this is correct

    If the new instance was launched without appending the security group that contains the SSH rule, or was attached to a different security group, the rule never applies to that instance. Security group membership is determined at launch time for the primary ENI, and editing rules on the intended group only affects instances that are actually associated with it. To resolve this, you must attach the correct security group to the running instance or relaunch with the right group selected.

  • ✗

    The security group is using the default VPC security group

    Why it's wrong here

    The default security group for a VPC is preconfigured to automatically allow inbound traffic from other instances in the same group, but it generally does not include a rule for SSH from an external IP. If the new instance was left in the default group rather than the custom one, the custom rule allowing port 22 would simply not be present on that instance's attached security group. You would need to explicitly add an SSH rule to the default group or reassign the instance to the group that already contains it.

  • ✗

    The security group is configured as stateless

    Why it's wrong here

    Security groups are always stateful in AWS, and there is no setting or configuration that makes them stateless. The stateful nature means that if you allow outbound traffic or an established session exists, the return packets for that session are automatically permitted without needing a separate inbound rule. Therefore, the claim that the security group is 'stateless' is not technically possible and cannot explain an SSH failure caused by the security group rules.

  • ✗

    The network ACL is blocking SSH traffic to the subnet

    Why it's wrong here

    Network ACLs operate at the subnet boundary and apply to every instance in that subnet, independently of the security groups assigned to each instance. They are stateless, so if they block inbound port 22 or the ephemeral return ports, SSH would fail despite a correct security group rule. However, this option describes a different firewall layer than the security group the question is about, and to truly be the cause the NACL would need to omit the SSH allow rule; merely saying the security group rule exists does not prove the NACL is misconfigured.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.