SCS-C02 Infrastructure Security Practice Question
A company runs a multi-tier web application on AWS. The web tier uses an Application Load Balancer (ALB) in a public subnet, and the application tier runs on EC2 instances in private subnets. The security team recently ran a vulnerability scan and found that the application instances are accessible from the internet on port 8080. The EC2 instances have a security group that allows inbound traffic on port 8080 from the ALB's security group only. However, the ALB's security group allows inbound traffic on port 8080 from 0.0.0.0/0. The architecture also includes a NAT Gateway for outbound internet access from private subnets. The security engineer needs to ensure that only the ALB can communicate with the application instances on port 8080, and that the application instances cannot be directly accessed from the internet. What should the security engineer do?
⚠ Common exam trap
SCS-C02 often tests the misconception that security groups support deny rules or that NACLs can substitute for SG least privilege — candidates must remember SGs are allow-only and that the fix is removing the overly permissive inbound rule, not adding a deny.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the ALB security group to remove the inbound rule for port 8080 from 0.0.0.0/0, and configure the ALB listener to forward traffic from port 80/443 to port 8080 on the target group.
The ALB security group should only allow inbound traffic on the listener ports (80/443) from the internet, not port 8080. The ALB listener then forwards to the target group on port 8080, and the EC2 security group already restricts 8080 to the ALB's security group. Removing the 0.0.0.0/0 rule on 8080 from the ALB SG closes the exposure while preserving the ALB-to-instance path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the EC2 instance security group to allow inbound traffic on port 8080 from 0.0.0.0/0, and rely on the subnet network ACL to block traffic.
Why it's wrong here
Allowing inbound traffic on port 8080 from 0.0.0.0/0 in the EC2 instance security group would let any internet client reach the instances directly, bypassing the ALB entirely. Relying on the subnet network ACL to block that traffic is unreliable because network ACLs are stateless and a deny-all rule for 0.0.0.0/0 on port 8080 would also block legitimate request forwarding from the ALB to the instances, breaking the application. Additionally, security groups and network ACLs operate independently, and an explicit security group allow cannot be "overridden" by a network ACL deny without also disrupting valid traffic paths.
- ✗
Add a rule to the EC2 security group that denies inbound traffic from 0.0.0.0/0 on port 8080.
Why it's wrong here
Security groups do not support deny rules; they are exclusively allow-list constructs, so adding a rule that denies inbound traffic from 0.0.0.0/0 on port 8080 is not possible. Even if such a rule were syntactically valid, the default behavior of a security group is to deny all inbound traffic unless an explicit allow rule exists, making the attempted deny redundant. The proper fix is to remove the permissive rule from the ALB security group and reconfigure the listener/target group, not to add an invalid rule to the EC2 instance security group.
- ✓
Modify the ALB security group to remove the inbound rule for port 8080 from 0.0.0.0/0, and configure the ALB listener to forward traffic from port 80/443 to port 8080 on the target group.
Why this is correct
This is the correct solution because it eliminates the unintended public exposure of port 8080 while still enabling the ALB to forward client traffic to the instances on that port. The ALB security group should only permit inbound HTTP/HTTPS on ports 80 and 443, and the ALB listener should be configured with a forward action to the target group on port 8080. Instance security groups should then independently restrict port 8080 to only accept traffic from the ALB security group, preserving a defense-in-depth architecture where instances are not directly internet-reachable.
- ✗
Place the EC2 instances in a public subnet and use a network ACL to block inbound traffic on port 8080 from the internet.
Why it's wrong here
Placing the EC2 instances in a public subnet would assign them public IP addresses and enable direct internet routing, which defeats the purpose of hiding them behind the ALB. A network ACL rule that blocks inbound port 8080 from the internet is stateless and requires corresponding outbound rules; it would also block legitimate ALB-to-instance traffic if applied to all sources, and it does nothing to protect other open ports. The instances should remain in private subnets, with security group rules that permit port 8080 only from the ALB security group, rather than relying on a public subnet and network ACL.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.