Courseiva
Infrastructure Security →hardMultiple Select

SCS-C02 Infrastructure Security Practice Question

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to allow only HTTP and HTTPS traffic from the internet to the ALB, and only HTTP traffic from the ALB to the EC2 instances. Which THREE security group configurations are required? (Choose three.)

⚠ Common exam trap

The trap here is that candidates often mistakenly add an HTTPS inbound rule to the EC2 security group (option D) or allow direct internet access to the instances (option B), failing to recognize that the ALB should handle HTTPS termination and only forward HTTP to the backend.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ALB security group: inbound rule allowing HTTP from 0.0.0.0/0.

The ALB must accept HTTP traffic from the internet (0.0.0.0/0) to serve web requests. This inbound rule allows the ALB to listen on port 80 for unencrypted HTTP traffic, which is a standard requirement for a public-facing web application. Without this rule, HTTP requests from clients would be dropped by the ALB's security group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ALB security group: inbound rule allowing HTTP from 0.0.0.0/0.

    Why this is correct

    The ALB is the public entry point for the web application, so its security group must permit inbound HTTP from any IPv4 address. Allowing 0.0.0.0/0 on port 80 is required for clients on the internet to reach the load balancer. The ALB then forwards requests to the EC2 instances, whose own security group controls traffic from the ALB only.

  • ✗

    EC2 security group: inbound rule allowing HTTP from 0.0.0.0/0.

    Why it's wrong here

    Opening HTTP from 0.0.0.0/0 on the EC2 instance security group would let internet clients bypass the load balancer entirely and connect directly to the instances. This defeats the architectural purpose of the ALB and exposes the instances to unrestricted inbound traffic. The correct pattern is to allow HTTP only from the ALB's security group, not from all IP addresses.

  • ✓

    EC2 security group: inbound rule allowing HTTP from ALB security group.

    Why this is correct

    The EC2 instances sit behind the ALB, so they should accept traffic only from the ALB, not directly from the internet. By referencing the ALB security group as the source, this rule restricts HTTP access to requests forwarded by the load balancer. It is a least-privilege approach that ensures only the ALB can reach the instances on port 80.

  • ✗

    EC2 security group: inbound rule allowing HTTPS from ALB security group.

    Why it's wrong here

    The ALB terminates inbound SSL/TLS connections, so traffic between the ALB and the backend EC2 instances is typically forwarded over HTTP, not HTTPS. Allowing HTTPS from the ALB security group on the instance side would expect encrypted connections that the ALB does not normally use for backend communication. The correct backend rule is inbound HTTP from the ALB security group, assuming the ALB listener forwards to port 80.

  • ✓

    ALB security group: inbound rule allowing HTTPS from 0.0.0.0/0.

    Why this is correct

    The ALB can be used to terminate HTTPS, so its security group must allow inbound HTTPS from the internet on port 443. This rule permits clients to establish encrypted connections to the load balancer, which then handles SSL termination before forwarding traffic to the instances. It is a valid configuration when the application uses HTTPS, and it pairs with a corresponding EC2 security group rule that allows HTTP from the ALB.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.