SCS-C02 Infrastructure Security Practice Question
A company uses AWS CloudFormation to deploy infrastructure. A security requirement states that no security group should allow inbound SSH access from 0.0.0.0/0. What is the best way to enforce this policy?
⚠ Common exam trap
Watch out — candidates often choose an IAM-based deny policy (Option A) thinking it prevents the action entirely, but they overlook that AWS Config with remediation is the only option that both detects and automatically fixes existing non-compliant security groups, which is the core requirement of 'enforcing' the policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Config with a managed rule to detect and automatically remediate non-compliant security groups.
AWS Config with a managed rule (e.g., 'restricted-ssh') can continuously evaluate security group configurations against the policy and automatically remediate non-compliant rules using AWS Systems Manager Automation. This provides detective and corrective enforcement without blocking legitimate administrative actions, unlike IAM or SCP approaches that would prevent necessary changes or fail to detect existing non-compliant resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM policy that denies the ec2:AuthorizeSecurityGroupIngress action if the CIDR is 0.0.0.0/0.
Why it's wrong here
An IAM policy denying ec2:AuthorizeSecurityGroupIngress cannot inspect the CIDR block because IAM condition keys do not expose the IP range being authorized in that API call. The ec2:AuthorizeSecurityGroupIngress action supports condition keys for resource tags and VPC, but not a key that evaluates the IpRanges request parameter. Therefore, this policy would either over-deny all ingress authorization or fail to discriminate against 0.0.0.0/0, making it ineffective for this specific restriction.
- ✓
Use AWS Config with a managed rule to detect and automatically remediate non-compliant security groups.
Why this is correct
AWS Config can continuously monitor security group configurations using the managed rule 'vpc-sg-open-only-to-authorized-ports', which flags security groups that allow unrestricted inbound access. When the rule detects a non-compliant security group, you can attach an automatic remediation action using an AWS Systems Manager Automation document such as AWS-RevokeSecurityGroupIngress. This removes the offending SSH 0.0.0.0/0 rule without requiring manual intervention, and AWS Config tracks compliance status in the dashboard.
- ✗
Add an AWS::IAM::Policy resource in the CloudFormation template to deny the rule.
Why it's wrong here
Adding an AWS::IAM::Policy resource to a CloudFormation template merely creates an IAM policy object, but it does not attach that policy to any principal or apply it to the environment. Even if the policy were attached, CloudFormation itself does not enforce the policy at runtime; the template defines resources while the policy only sits in IAM. Moreover, the stack's own creation of the security group rule is performed by the service role or user, so unless that principal's effective permissions deny the action, the rule gets created regardless. CloudFormation templates are declarative infrastructure definitions, not security guardrails.
- ✗
Use a service control policy (SCP) that denies the CreateStack action if the template contains SSH from 0.0.0.0/0.
Why it's wrong here
Service control policies (SCPs) act as permission boundaries for AWS accounts, but they can only restrict AWS actions based on condition keys that AWS defines for those actions. The cloudformation:CreateStack action has no condition key that examines the template body or URL for resource definitions such as an SSH rule. Consequently, an SCP cannot deny CreateStack based on template content, and the stack would be created while SCPs only filter API calls at a coarse-grained level. You would need a pre-deployment validation mechanism like CloudFormation Hooks.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.