SCS-C02 Security Group Practice Question
A company uses Amazon GuardDuty to monitor for threats. The security team receives a high-severity finding: 'UnauthorizedAccess:EC2/SSHBruteForce'. The finding indicates a single EC2 instance with a public IP is receiving SSH connection attempts from multiple external IPs. The instance is part of an Auto Scaling group and is fronted by an Application Load Balancer (ALB). The security team wants to block the attacking IPs without disrupting legitimate traffic. What is the MOST effective approach?
⚠ Common exam trap
The trap is that candidates assume AWS WAF can block any type of traffic when attached to an ALB, but WAF only inspects HTTP/HTTPS requests at Layer 7, not SSH traffic at Layer 4. The correct approach is to use a security group to block SSH at the instance level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the security group of the EC2 instance to deny inbound SSH from the attacking IPs.
Modifying the security group of the EC2 instance to deny inbound SSH from the attacking IPs directly blocks the SSH brute force attempts at the instance level. Since the instance is part of an Auto Scaling group, security group modifications will apply to all instances launched with that security group, and updates are immediate. Option D (AWS WAF on ALB) is ineffective because WAF only inspects HTTP/HTTPS traffic at Layer 7, while SSH traffic operates at Layer 4 and does not pass through the ALB; the ALB only handles HTTP/HTTPS, not SSH. The attackers are targeting the instance's public IP directly over SSH, not through the ALB. Therefore, WAF cannot block SSH traffic. Option A (stop instance) is disruptive and unnecessary. Option C (network ACL) would block traffic at the subnet level but would affect all instances in the subnet and is less granular than a security group.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stop the EC2 instance and launch a new one in a different subnet.
Why it's wrong here
Stopping the EC2 instance and launching a new one in a different subnet is disruptive and does not address the root cause; the new instance would still be vulnerable to the same attackers if the security group is not updated.
- ✓
Modify the security group of the EC2 instance to deny inbound SSH from the attacking IPs.
Why this is correct
Modifying the security group to deny inbound SSH from the attacking IPs directly blocks the SSH brute force attempts at the instance level. Since the instance uses a security group that can be applied to all instances in the Auto Scaling group, this approach is effective and persistent.
- ✗
Create a network ACL rule on the subnet to deny inbound traffic from the attacking IPs.
Why it's wrong here
Creating a network ACL rule to deny inbound traffic from the attacking IPs would block traffic at the subnet level, affecting all instances in the subnet. However, network ACLs are stateless and require separate inbound and outbound rules, making them less granular and harder to manage than security groups for this use case.
- ✗
Configure AWS WAF on the ALB to block the attacking IPs using an IP set rule.
Why it's wrong here
AWS WAF on an ALB only inspects HTTP/HTTPS traffic, not SSH traffic. SSH traffic goes directly to the instance's public IP and does not pass through the ALB. Therefore, WAF cannot block SSH brute force attempts.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 376 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.