SCS-C02 Infrastructure Security Practice Question
A security engineer is designing a network ACL for a public subnet containing an Application Load Balancer. The subnet must allow inbound HTTPS traffic from the internet and outbound traffic to the internet for patches. Which inbound rule should be added?
⚠ Common exam trap
It's easy for candidates to confuse stateless network ACLs with stateful security groups, leading them to think an ephemeral port rule (like option A) is needed for inbound traffic, when in fact the inbound rule must specify the destination port 443 for the initial connection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow TCP port 443 from 0.0.0.0/0
HTTPS traffic uses TCP port 443, and the network ACL must explicitly allow inbound TCP traffic on port 443 from the internet (0.0.0.0/0) to reach the Application Load Balancer. Network ACLs are stateless, so each direction requires a separate rule; this inbound rule permits the initial HTTPS connection requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow TCP port 1024-65535 from 0.0.0.0/0
Why it's wrong here
Opening inbound TCP ports 1024–65535 to 0.0.0.0/0 mistakenly treats the ephemeral client port range as a server-side destination. Ephemeral ports are used by outbound connections to receive return traffic, not by clients attempting to reach a public HTTPS web server. An inbound NACL rule that allows the entire high port range exposes every service bound to those ports and violates least-privilege access. Only the specific destination port the service listens on, such as TCP 443 for HTTPS, should be allowed inbound.
- ✗
Allow UDP port 443 from 0.0.0.0/0
Why it's wrong here
Allowing UDP port 443 does not enable standard HTTPS, because HTTPS operates as HTTP over TLS carried by TCP, which requires a TCP three-way handshake. A UDP rule is irrelevant for that protocol and, if permitted, only adds exposure for unrelated UDP-based services such as QUIC or DNS over QUIC without satisfying the requirement. Stateless NACLs do not translate or convert protocols, so UDP 443 cannot substitute for the needed TCP 443 rule. The correct action is to permit TCP 443, not UDP.
- ✗
Allow all traffic from 0.0.0.0/0
Why it's wrong here
Creating an inbound NACL rule that allows all traffic from 0.0.0.0/0 opens every TCP and UDP port to the public internet, including administrative, database, and unmanaged services, dramatically increasing the attack surface. This violates the fundamental security principle of least privilege and fails to differentiate between legitimate web traffic and malicious probes. Because NACLs are stateless, the allow-all rule applies to every packet independently, compounding the risk by permitting both inbound connection attempts and unsolicited traffic across all ports. A proper design should enumerate only the exact protocols and ports needed for the intended service.
- ✓
Allow TCP port 443 from 0.0.0.0/0
Why this is correct
This is the correct and most restrictive inbound rule for a public HTTPS endpoint because HTTPS is implemented with TLS over TCP and defaults to destination port 443. Allowing TCP 443 from 0.0.0.0/0 enables any internet client to initiate a TCP connection and perform a TLS handshake with the web server. Because NACLs are stateless, you must also configure a separate outbound rule allowing the ephemeral port range (1024–65535) so the server's return traffic can reach that client. Restricting the inbound rule to TCP 443 avoids exposing other ports while still meeting the functional requirement.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.