Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A security engineer is designing a multi-tier web application. The application uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances in private subnets. The engineer needs to ensure that the EC2 instances only accept traffic from the ALB and not from any other source. Which security group configuration should the engineer use?

⚠ Common exam trap

Watch out — candidates often think they need to use the ALB's public IP address (Option A) or the VPC CIDR (Option B) as the source, not realizing that security group referencing is the correct and more secure method for allowing traffic from an ALB to backend instances.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow inbound HTTP traffic from the ALB's security group on the EC2 instances' security group.

It uses a security group reference to allow inbound HTTP traffic from the ALB's security group. This ensures that only traffic originating from the ALB (which has that security group attached) can reach the EC2 instances, regardless of the ALB's IP addresses or changes in the VPC CIDR. This is the recommended AWS best practice for securing traffic between an ALB and backend instances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow inbound HTTP traffic from the ALB's public IP address on the EC2 instances' security group.

    Why it's wrong here

    The ALB's public IP addresses are not a reliable source for a security group rule because the ALB's traffic to the instances originates from its private IP addresses (the ENIs inside the VPC), not its public IPs. Furthermore, public IPs associated with an ALB are dynamically assigned and can change when the load balancer scales or is replaced. This rule would fail to match the actual source and could also cause loss of connectivity if the IP changes.

  • ✗

    Allow inbound HTTP traffic from the VPC CIDR range on the EC2 instances' security group.

    Why it's wrong here

    Using the VPC CIDR range as the source allows inbound HTTP traffic from any resource within the VPC, including other EC2 instances, containers, or Lambda functions that may be compromised. This expands the attack surface far beyond the ALB, because any host with an IP in the CIDR can reach the web instances directly. A security group rule should be scoped narrowly to the specific source security group of the ALB, not the entire network.

  • ✓

    Allow inbound HTTP traffic from the ALB's security group on the EC2 instances' security group.

    Why this is correct

    This is correct because referencing the ALB's security group as the source limits inbound HTTP to only traffic originating from the ALB's elastic network interfaces. When the ALB forwards requests to the instances, it uses its ENIs as the source IPs, which are associated with the ALB's security group, so such traffic matches the rule. Any other traffic, including direct internet access, is implicitly denied, providing a least-privilege security control.

  • ✗

    Allow inbound HTTP traffic from 0.0.0.0/0 on the EC2 instances' security group.

    Why it's wrong here

    Allowing 0.0.0.0/0 on the instances' security group permits HTTP access from any public internet host, bypassing the ALB as a mandatory front-end. This exposes the instances directly to the internet, increasing the risk of attacks such as SQL injection or port scanning. The ALB's security group reference is the only way to guarantee traffic must pass through the load balancer.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.