SCS-C02 Infrastructure Security Practice Question
A company is using an Application Load Balancer (ALB) to distribute traffic to a set of EC2 instances in private subnets. The security team wants to ensure that only traffic from the ALB can reach the EC2 instances. Which security group configuration should be applied to the EC2 instances?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow inbound HTTP/HTTPS from the security group attached to the ALB.
Referencing the security group of the Application Load Balancer as the source in the inbound rule ensures that only traffic coming from the ALB can reach the EC2 instances. Option B is incorrect because network ACLs are stateless and cannot reference security groups; they also operate at the subnet level, not at the instance level. Option C is incorrect because allowing traffic from 0.0.0.0/0 would expose the instances to the internet. Option D is incorrect because allowing traffic from the VPC CIDR would permit any instance in the VPC to access the EC2 instances, not just the ALB.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Allow inbound HTTP/HTTPS from the security group attached to the ALB.
Why this is correct
Referencing the ALB's security group as the source is a security group-to-security group rule: it dynamically matches any IP address associated with an elastic network interface that belongs to that ALB security group. This means EC2 instances behind the ALB accept traffic only from the ALB's ENIs, even as the ALB scales and its private IPs change. The rule is stateful, so return traffic flows automatically, and no internet CIDR is ever exposed. This is the AWS-recommended pattern for placing an ALB in front of a web tier.
- ✗
Configure the network ACL to allow traffic from the ALB's private IP addresses.
Why it's wrong here
Network ACLs are stateless and cannot reference security groups, so you cannot specify "traffic from the ALB SG" in a NACL rule; you must use an explicit CIDR or IP range. Using the ALB's private IP addresses is brittle because ALB nodes are distributed across subnets and their private addresses can be replaced by scaling or rebalancing. Additionally, NACLs require separate inbound and outbound rules with ephemeral port ranges, making this a needlessly complex and error-prone solution. The correct way to constrain traffic at the instance level is a security group rule, not a NACL.
- ✗
Allow inbound HTTP/HTTPS from 0.0.0.0/0.
Why it's wrong here
Allowing 0.0.0.0/0 means any host on the internet can reach the instances' HTTP/HTTPS ports directly, bypassing the ALB entirely. This defeats the purpose of using an ALB as the sole ingress point and removes the ALB's protections, such as request routing, idle timeout, and TLS termination. The instances' security group should only trust the ALB's security group, never an unrestricted CIDR. For a clean architecture, drop all direct internet access to the web tier.
- ✗
Allow inbound HTTP/HTTPS from the VPC CIDR block.
Why it's wrong here
Allowing the VPC CIDR grants every resource inside the VPC—not just the ALB—permission to directly access the instances on HTTP/HTTPS. This includes other EC2 instances, Lambda functions using VPC networking, and any peered VPC traffic routed within the CIDR, creating a broader attack surface. A compromised non-ALB instance could then pivot directly to the web servers. The rule should land on the ALB's security group, not on a broad range that cannot distinguish ALB traffic from any other intra-VPC host.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.