Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to allow its developers to SSH into EC2 instances only from the corporate network IP range (203.0.113.0/24). Which configuration should be used to enforce this restriction?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a security group rule that allows inbound SSH (port 22) from the corporate IP range.

A security group rule can restrict inbound SSH to the specific IP range. Security groups act as a virtual firewall for EC2 instances, and by adding a rule that allows inbound SSH only from the corporate IP range (203.0.113.0/24), all other inbound traffic on port 22 is implicitly denied. Option A is incorrect because network ACLs are stateless and apply at the subnet level, not the instance level, and the question asks for a configuration to enforce SSH restriction on EC2 instances. Option B is incorrect because AWS Systems Manager Session Manager does not use SSH; it provides browser-based shell access without inbound ports. Option C is incorrect because IAM policies control permissions for API actions, not network traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a network ACL on the subnet to allow inbound SSH from the corporate range and deny all other inbound traffic.

    Why it's wrong here

    A network ACL is stateless, meaning it evaluates inbound and outbound traffic independently; even if inbound SSH from 203.0.113.0/24 is allowed, the corresponding outbound response traffic must also be explicitly permitted, which the option does not specify. This option is tempting because network ACLs are commonly used for subnet-level IP-based filtering, and in a scenario where the application does not require stateful tracking of return traffic—such as blocking specific inbound ports without needing to manage ephemeral outbound replies—a network ACL would be the correct choice.

  • ✗

    Use AWS Systems Manager Session Manager to connect to instances instead of SSH.

    Why it's wrong here

    AWS Systems Manager Session Manager is a valid way to avoid opening port 22 entirely, but the question asks to restrict SSH access specifically. Session Manager establishes a connection through the SSM agent without requiring inbound network rules, yet it does not modify or override the existing security group that still allows SSH from non-corporate IPs. Because the security group rule permitting SSH from all IP ranges remains unchanged, simply adopting Session Manager does not enforce the stated restriction, and the SSH service could still be reachable by unauthorized sources.

  • ✗

    Add an IAM policy that allows `ec2:RunInstances` only if the request includes the corporate IP.

    Why it's wrong here

    An IAM policy with ec2:RunInstances and a condition on the corporate IP governs the API call that launches the instance, not the network traffic to a running instance. The aws:SourceIp condition key evaluates the IP address of the caller making the RunInstances request, but after the instance is running, that policy has no effect on the security group rules or NACL rules that determine whether an SSH connection is allowed. Since IAM does not mediate host-level network connections, this approach fails to restrict inbound SSH traffic and is therefore incorrect.

  • ✓

    Add a security group rule that allows inbound SSH (port 22) from the corporate IP range.

    Why this is correct

    Adding a security group rule to allow inbound SSH (port 22) only from the corporate IP range is the correct solution because security groups are stateful and act at the instance's network interface level. This rule denies all other inbound SSH traffic by default, since security groups have an implicit deny-all inbound rule, and because it is stateful, return traffic for allowed connections (e.g., ephemeral ports) is automatically permitted. This directly restricts SSH to the corporate range without requiring separate outbound rules, making it the appropriate mechanism for this use case.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.