SCS-C02 Infrastructure Security Practice Question
A security engineer is configuring a Network ACL for a public subnet that hosts a web server. The web server must accept HTTPS (TCP 443) traffic from the internet and respond. It must also be able to initiate outbound connections to the internet for software updates (HTTPS). What is the MINIMUM set of rules required for the inbound and outbound Network ACL?
⚠ Common exam trap
The trap here is that candidates often forget that Network ACLs are stateless and assume that allowing inbound HTTPS automatically permits the return traffic, leading them to choose option C instead of the more precise option D that includes ephemeral port rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inbound: allow TCP 443 from 0.0.0.0/0; Outbound: allow TCP 1024-65535 to 0.0.0.0/0 (for return traffic) and allow TCP 443 to 0.0.0.0/0 (for updates).
Network ACLs are stateless, meaning they require explicit rules for both inbound and outbound traffic. For the web server to accept HTTPS requests from the internet, an inbound rule allowing TCP 443 from 0.0.0.0/0 is needed. For the server to respond to those requests, an outbound rule allowing ephemeral ports (TCP 1024-65535) to 0.0.0.0/0 is required to handle return traffic. Additionally, to allow the server to initiate outbound HTTPS connections for software updates, a separate outbound rule allowing TCP 443 to 0.0.0.0/0 is necessary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inbound: allow TCP 443 from 0.0.0.0/0 and TCP 22 from a management IP; Outbound: allow all traffic to 0.0.0.0/0.
Why it's wrong here
Allowing inbound TCP 443 for public web traffic and TCP 22 from a management IP is reasonable, but the outbound rule permitting all traffic to 0.0.0.0/0 violates the principle of least privilege. Because network ACLs are stateless, the outbound rule also controls response traffic, but it also would allow an attacker to exfiltrate data to any destination if the instance is compromised. Moreover, exposing SSH (port 22) widens the attack surface and is unnecessary if not explicitly required for management, and outbound all makes the rule set unnecessarily permissive.
- ✗
Inbound: allow TCP 443 from 0.0.0.0/0; Outbound: allow TCP 443 to a specific software update server IP.
Why it's wrong here
This configuration fails to account for the stateless nature of network ACLs: inbound responses to clients' HTTPS connections arrive with a destination port in the ephemeral range (1024-65535), and without an outbound rule allowing that range, replies will be dropped. The outbound TCP 443 rule to a single update server IP also assumes a static address, but software update endpoints often use multiple IPs or change via DNS, causing updates to fail. While restricting outbound updates to HTTPS is good, the rule set is both functionally incomplete and operationally brittle.
- ✗
Inbound: allow TCP 443 from 0.0.0.0/0; Outbound: allow all traffic to 0.0.0.0/0.
Why it's wrong here
Allowing all outbound traffic is a common misconfiguration because it provides no egress filtering, meaning a compromised instance can communicate with any host on the internet, including command-and-control servers. Although this rule set would allow HTTPS responses and outbound updates to work, it is not a minimal rule set and fails the security requirement of least privilege. The correct approach is to permit only the necessary ephemeral return ports and outbound HTTPS, not blanket egress.
- ✓
Inbound: allow TCP 443 from 0.0.0.0/0; Outbound: allow TCP 1024-65535 to 0.0.0.0/0 (for return traffic) and allow TCP 443 to 0.0.0.0/0 (for updates).
Why this is correct
This rule set meets the requirement by allowing inbound HTTPS on 443 for public clients and providing the minimal outbound rules needed for stateful-like behavior in a stateless NACL. The outbound TCP 1024-65535 rule allows responses to return to clients' ephemeral source ports, while the outbound TCP 443 rule permits the instance to fetch software updates. Together they allow required traffic while blocking unnecessary outbound communication, aligning with least privilege and the scenario's goal.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.