Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is running a critical web application on EC2 instances behind an Application Load Balancer (ALB) in a VPC. The application serves traffic on port 443. The security team has implemented a security group for the ALB that allows inbound HTTPS from 0.0.0.0/0. The EC2 instances are in a private subnet with a security group that allows inbound traffic from the ALB security group on port 8080. The application works correctly. However, the security team wants to add an additional layer of defense by implementing a web application firewall (WAF) to block common web exploits. The team also wants to ensure that only traffic from the company's corporate IP range (203.0.113.0/24) can access the application for administrative purposes on a separate path. The team has enabled AWS WAF on the ALB and associated a web ACL. They have also created a rule to allow traffic from the corporate IP range and block all other traffic. After deploying these changes, external users (not from corporate IP) cannot access the application at all. The company wants external users to be able to access the main application, but only corporate IPs should access the admin path. What should the security engineer do to fix the issue?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the WAF rule to allow traffic from the corporate IP range on the admin path and allow all traffic on the main application path.

The correct action is to modify the WAF rule to allow traffic from corporate IPs on the admin path and allow all other traffic on the main application path. Currently, the WAF rule blocks all non-corporate traffic, which prevents external users from accessing the main application. By creating separate conditions for the admin path (corporate IPs only) and the main path (allow all), the security team can achieve the desired access control. Option A is incorrect because it would block external users at the security group level. Option B is unnecessary and adds complexity. Option C removes the WAF protection entirely. Therefore, option D is the correct solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the security group of the ALB to allow only corporate IPs.

    Why it's wrong here

    Restricting the ALB security group to corporate IPs would block all inbound connections to the load balancer, including the public main application path, because security groups filter at the network layer using source IP and port without any awareness of HTTP URI paths. This would deny service to all external customers while also failing to provide the required path-specific separation, as both admin and main traffic share the same ALB endpoint.

  • ✗

    Create two separate ALBs, one for admin traffic and one for main traffic.

    Why it's wrong here

    Deploying two separate ALBs for admin and main traffic introduces unnecessary infrastructure complexity and recurring costs, requiring separate DNS records, TLS certificates, and security group rules for each load balancer. It still does not address the existing WAF rule that blocks all non-corporate traffic, unless you also rework the WAF configuration per ALB. The most efficient solution is to leverage a single ALB with path-aware WAF rules to enforce conditional access based on the URI.

  • ✗

    Remove the WAF rule that blocks all non-corporate traffic and rely on security groups.

    Why it's wrong here

    Removing the WAF rule that blocks non-corporate traffic and relying solely on security groups would immediately expose the admin path to the entire internet because security groups can only filter by IP, port, and protocol—they cannot inspect HTTP path patterns like /admin. This approach eliminates the corporate IP restriction entirely, leaving the admin interface wide open while offering no mechanism to distinguish between admin and main application traffic.

  • ✓

    Modify the WAF rule to allow traffic from the corporate IP range on the admin path and allow all traffic on the main application path.

    Why this is correct

    Modify the WAF web ACL rule so it permits requests from the corporate IP range when the URI path is /admin*, while allowing all other traffic to the main application path without restriction. This can be implemented as a rule with a condition combining the IP set source match and a string pattern match for the admin path, with an appropriate action to block non-matching admin requests. This preserves the public availability of the main application and maintains a tight security boundary on administrative endpoints.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.