Courseiva
Security Logging and MonitoringhardMultiple ChoiceObjective-mapped

SCS-C02 Security Group Practice Question

A company uses Amazon GuardDuty to monitor for threats. The security team receives a high-severity finding: 'UnauthorizedAccess:EC2/SSHBruteForce'. The finding indicates a single EC2 instance with a public IP is receiving SSH connection attempts from multiple external IPs. The instance is part of an Auto Scaling group and is fronted by an Application Load Balancer (ALB). The security team wants to block the attacking IPs without disrupting legitimate traffic. What is the MOST effective approach?

⚠ Common exam trap

The trap is that candidates assume AWS WAF can block any type of traffic when attached to an ALB, but WAF only inspects HTTP/HTTPS requests at Layer 7, not SSH traffic at Layer 4. The correct approach is to use a security group to block SSH at the instance level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Modify the security group of the EC2 instance to deny inbound SSH from the attacking IPs.

Modifying the security group of the EC2 instance to deny inbound SSH from the attacking IPs directly blocks the SSH brute force attempts at the instance level. Since the instance is part of an Auto Scaling group, security group modifications will apply to all instances launched with that security group, and updates are immediate. Option D (AWS WAF on ALB) is ineffective because WAF only inspects HTTP/HTTPS traffic at Layer 7, while SSH traffic operates at Layer 4 and does not pass through the ALB; the ALB only handles HTTP/HTTPS, not SSH. The attackers are targeting the instance's public IP directly over SSH, not through the ALB. Therefore, WAF cannot block SSH traffic. Option A (stop instance) is disruptive and unnecessary. Option C (network ACL) would block traffic at the subnet level but would affect all instances in the subnet and is less granular than a security group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Stop the EC2 instance and launch a new one in a different subnet.

    Why it's wrong here

    Stopping the EC2 instance and launching a new one in a different subnet is disruptive and does not address the root cause; the new instance would still be vulnerable to the same attackers if the security group is not updated.

  • Modify the security group of the EC2 instance to deny inbound SSH from the attacking IPs.

    Why this is correct

    Modifying the security group to deny inbound SSH from the attacking IPs directly blocks the SSH brute force attempts at the instance level. Since the instance uses a security group that can be applied to all instances in the Auto Scaling group, this approach is effective and persistent.

  • Create a network ACL rule on the subnet to deny inbound traffic from the attacking IPs.

    Why it's wrong here

    Creating a network ACL rule to deny inbound traffic from the attacking IPs would block traffic at the subnet level, affecting all instances in the subnet. However, network ACLs are stateless and require separate inbound and outbound rules, making them less granular and harder to manage than security groups for this use case.

  • Configure AWS WAF on the ALB to block the attacking IPs using an IP set rule.

    Why it's wrong here

    AWS WAF on an ALB only inspects HTTP/HTTPS traffic, not SSH traffic. SSH traffic goes directly to the instance's public IP and does not pass through the ALB. Therefore, WAF cannot block SSH brute force attempts.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 376 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.