SCS-C02 Infrastructure Security Practice Question
A company uses an Application Load Balancer (ALB) to distribute traffic to a fleet of EC2 instances in private subnets. The security team wants to ensure that only the ALB can communicate with the EC2 instances. Which security group configuration should be applied to the EC2 instances?
⚠ Common exam trap
Candidates often confuse security group referencing with CIDR-based rules, mistakenly thinking that allowing the VPC CIDR (Option C) is sufficient, but this would allow any resource in the VPC, not just the ALB, to reach the EC2 instances.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow inbound HTTP traffic from the ALB's security group
Security groups can reference other security groups as a source, allowing traffic only from resources associated with that security group. By specifying the ALB's security group as the source for inbound HTTP traffic, the EC2 instances will only accept traffic originating from the ALB, effectively restricting all other inbound traffic. This is a best practice for securing backend instances behind a load balancer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow inbound HTTP traffic from the EC2 instances' own security group
Why it's wrong here
Referencing the instances' own security group as the source permits instance-to-instance traffic, not traffic originating from the ALB, so any instance can reach its peers directly. It is tempting because self-referencing rules are common for tiered fleets, and would suit intra-tier communication rather than restricting ingress to the load balancer.
- ✗
Allow inbound HTTP traffic from 0.0.0.0/0
Why it's wrong here
0.0.0.0/0 opens HTTP to every internet source, including direct connections that bypass the ALB entirely, defeating the requirement. It is tempting because it guarantees the ALB's health checks succeed, and would suit public-facing web servers, but here the ALB's security group must be the referenced source.
- ✗
Allow inbound HTTP traffic from the VPC CIDR block
Why it's wrong here
Opening port 80 to the whole VPC CIDR lets any instance in the VPC reach the EC2 fleet, not just the ALB, so it fails the requirement. It is tempting because VPC-scoped rules are common for internal tiers, but the correct configuration references the ALB's security group as the source.
- ✓
Allow inbound HTTP traffic from the ALB's security group
Why this is correct
Referencing the ALB's security group as the source means the EC2 instances accept traffic only from ENIs belonging to that group, regardless of IP addresses. This satisfies the stem's constraint that only the ALB may communicate with the instances.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.