Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company uses an Application Load Balancer (ALB) to distribute traffic to a fleet of EC2 instances in private subnets. The security team wants to ensure that only the ALB can communicate with the EC2 instances. Which security group configuration should be applied to the EC2 instances?

⚠ Common exam trap

Candidates often confuse security group referencing with CIDR-based rules, mistakenly thinking that allowing the VPC CIDR (Option C) is sufficient, but this would allow any resource in the VPC, not just the ALB, to reach the EC2 instances.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow inbound HTTP traffic from the ALB's security group

Security groups can reference other security groups as a source, allowing traffic only from resources associated with that security group. By specifying the ALB's security group as the source for inbound HTTP traffic, the EC2 instances will only accept traffic originating from the ALB, effectively restricting all other inbound traffic. This is a best practice for securing backend instances behind a load balancer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow inbound HTTP traffic from the EC2 instances' own security group

    Why it's wrong here

    Referencing the instances' own security group as the source permits instance-to-instance traffic, not traffic originating from the ALB, so any instance can reach its peers directly. It is tempting because self-referencing rules are common for tiered fleets, and would suit intra-tier communication rather than restricting ingress to the load balancer.

  • ✗

    Allow inbound HTTP traffic from 0.0.0.0/0

    Why it's wrong here

    0.0.0.0/0 opens HTTP to every internet source, including direct connections that bypass the ALB entirely, defeating the requirement. It is tempting because it guarantees the ALB's health checks succeed, and would suit public-facing web servers, but here the ALB's security group must be the referenced source.

  • ✗

    Allow inbound HTTP traffic from the VPC CIDR block

    Why it's wrong here

    Opening port 80 to the whole VPC CIDR lets any instance in the VPC reach the EC2 fleet, not just the ALB, so it fails the requirement. It is tempting because VPC-scoped rules are common for internal tiers, but the correct configuration references the ALB's security group as the source.

  • ✓

    Allow inbound HTTP traffic from the ALB's security group

    Why this is correct

    Referencing the ALB's security group as the source means the EC2 instances accept traffic only from ENIs belonging to that group, regardless of IP addresses. This satisfies the stem's constraint that only the ALB may communicate with the instances.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.