Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company runs a web application on EC2 instances in an Auto Scaling group across two Availability Zones. The instances are behind an Application Load Balancer. The security team wants to ensure that only the ALB can send traffic to the instances. The instances are in a security group named 'app-sg'. Currently, 'app-sg' has an inbound rule allowing HTTP traffic from 0.0.0.0/0. The team wants to restrict access to only the ALB's security group. The ALB is in a security group named 'alb-sg'. Which course of action should the security engineer take to meet the requirement with minimal disruption?

⚠ Common exam trap

Candidates often think they need to use the ALB's private IP addresses or ENI details, but AWS security groups support referencing other security groups by ID, which is the correct and scalable method for this use case.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the inbound rule of 'app-sg' to allow HTTP traffic from security group 'alb-sg'.

Security groups can reference each other by ID, allowing traffic from any instance associated with the source security group (alb-sg) without needing to know the ALB's IP addresses. This ensures that only the ALB can send HTTP traffic to the EC2 instances, as the rule dynamically applies to all ALB nodes across Availability Zones. It also minimizes disruption because no IP changes are required, and the rule automatically scales with the ALB.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the inbound rule of 'app-sg' to allow HTTP traffic from the private IP addresses of the ALB nodes.

    Why it's wrong here

    Hardcoding the private IPs of ALB nodes as the source in an inbound rule is brittle because the ALB scales automatically and its node IPs are dynamic and unpredictable. Security group rules cannot dynamically track a changing list of IPs, so you would need to continuously monitor and edit the rule manually. Moreover, using raw IPs ties access to specific infrastructure rather than the ALB's logical identity, and those same private IPs may belong to other instances.

  • ✗

    Modify the inbound rule of 'app-sg' to allow HTTPS traffic from 0.0.0.0/0 and remove the HTTP rule.

    Why it's wrong here

    Opening HTTPS to 0.0.0.0/0 defeats the purpose of placing an Application Load Balancer in front of the EC2 instances, because it allows any internet client to reach the web servers directly. It also assumes the ALB will use HTTPS to forward to the backend, which is not the default; if the target group uses HTTP, removing the HTTP rule would break load-balanced traffic. A security group source should restrict traffic to the ALB's security group, not accept all IPv4 addresses.

  • ✗

    Modify the inbound rule of 'app-sg' to allow HTTP traffic from the ALB's elastic network interface (ENI).

    Why it's wrong here

    A security group inbound rule's source must be an IPv4/IPv6 CIDR or another security group ID; you cannot reference an ENI ID as the source. Even if you could, ALB ENIs are dynamically created and removed as the load balancer scales, so pinning to a specific ENI would be fragile and require manual updates. Security group ID references remain valid as the ALB's underlying ENIs change, making that approach the intended AWS-native pattern.

  • ✓

    Modify the inbound rule of 'app-sg' to allow HTTP traffic from security group 'alb-sg'.

    Why this is correct

    Setting the source of the app-sg inbound rule to the alb-sg security group creates an identity-based dependency: only traffic originating from network interfaces associated with alb-sg is permitted. This automatically accommodates ALB node IP changes and scale events because AWS resolves the security group relationship in the VPC. It is a best practice for internal load-balanced architectures and is preferred over CIDR/ENI references since it remains valid across AZs and lifecycle changes.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.