SCS-C02 Infrastructure Security Practice Question
A security engineer is reviewing the security group rules for a web server. The security group currently has the following inbound rules: allow HTTP from 0.0.0.0/0, allow HTTPS from 0.0.0.0/0, and allow SSH from 0.0.0.0/0. Which change should the engineer make to improve security?
⚠ Common exam trap
Many exam-takers think restricting SSH to the VPC CIDR (Option B) is sufficient, but the exam expects you to recognize that the VPC CIDR can include many hosts, and the most secure approach is to limit to the specific administrative IP range, not just the internal network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the SSH rule to allow from a specific IP range used by the company's administrators.
Restricting SSH access (TCP port 22) to a specific IP range used by the company's administrators follows the principle of least privilege. The current rule allows SSH from 0.0.0.0/0, which exposes the server to brute-force attacks and unauthorized access from the entire internet. By limiting the source to only trusted administrative IPs, the attack surface is significantly reduced while still allowing necessary remote management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the HTTP rule and keep only HTTPS.
Why it's wrong here
Removing the HTTP rule and keeping only HTTPS is incorrect because many applications intentionally listen on port 80 to issue 301/302 redirects to HTTPS or to serve lightweight content to older clients that do not support TLS. Security groups are stateful, so simply removing the inbound rule will not terminate existing sessions, but new HTTP requests will be dropped, causing accessibility failures for those clients. Additionally, operational tooling such as HTTP-based health checks from load balancers or monitoring services may rely on port 80, so the rule should remain unless the application is explicitly HTTPS-only.
- ✗
Change the SSH rule to allow from the VPC CIDR only.
Why it's wrong here
Restricting SSH to the VPC CIDR only is wrong for two distinct reasons: it is simultaneously too broad and too narrow. The VPC CIDR covers every resource inside the VPC (including compromised instances and internal hosts), so it grants SSH access to a much wider set of principals than just the administrators. At the same time, it excludes administrators who connect from an external corporate network or a VPN egress IP, leaving them unable to reach the instance. A properly scoped rule should reference the administrators' public or private IP range, or a bastion security group, not the entire VPC.
- ✓
Change the SSH rule to allow from a specific IP range used by the company's administrators.
Why this is correct
This is correct because it follows the principle of least privilege by limiting SSH inbound traffic to the specific IP range (or security group) that represents the company's administrators. By restricting the source to known administrative egress addresses, the attack surface is dramatically reduced and unauthorized internal or external actors cannot initiate SSH connections. For a production web tier, SSH should typically be allowed only from a bastion jump host or a dedicated admin VPN CIDR, not from a broad public range. This ensures that only authenticated, expected users can establish a management session.
- ✗
Add a rule to allow ICMP from 0.0.0.0/0.
Why it's wrong here
Allowing ICMP from 0.0.0.0/0 is unnecessary and increases the attack surface by exposing the instance to network mapping and reconnaissance techniques such as ping sweeps and traceroute. ICMP traffic is not required for HTTP/HTTPS web serving, and if diagnostic tools are needed, rules should be scoped to specific ICMP types (e.g., Echo Request) and to trusted monitoring or operations IP ranges. Broad ICMP access also makes the instance a potential participant in reflected denial-of-service activity, so it should never be added unless there is a specific operational requirement.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.