SCS-C02 Infrastructure Security Practice Question
A security engineer needs to restrict outbound traffic from a VPC to only allow HTTPS traffic to specific domains (e.g., api.example.com). The VPC has a NAT gateway in a public subnet. What is the most secure way to implement this restriction?
⚠ Common exam trap
Candidates often assume network ACLs or security groups can filter by domain name, but they operate only at Layers 3 and 4, whereas domain filtering requires Layer 7 inspection provided by AWS Network Firewall.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy an AWS Network Firewall in the VPC and configure domain filtering rules.
AWS Network Firewall provides stateful, application-layer inspection that can filter outbound HTTPS traffic based on domain names (SNI/TLS hostnames), not just IP addresses. This allows you to restrict traffic to specific domains like api.example.com even if their IP addresses change, which is more secure and manageable than IP-based rules. Security groups and network ACLs cannot filter by domain name, and VPC endpoints are for specific AWS services, not general HTTPS domains.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure security group egress rules to allow HTTPS to 0.0.0.0/0.
Why it's wrong here
Security group egress rules operate only at layers 3 and 4, filtering by IP protocol and port number; they cannot inspect application-layer data such as the hostname in a TLS handshake. Allowing HTTPS to 0.0.0.0/0 permits outbound connections to any destination IP on port 443, so every domain would be reachable. This rule therefore provides no restriction to the allowed domains and fails the security requirement.
- ✓
Deploy an AWS Network Firewall in the VPC and configure domain filtering rules.
Why this is correct
AWS Network Firewall is a managed, stateful intrusion prevention system that can perform application-layer inspection of outbound traffic, including domain name filtering. It can decrypt TLS traffic via TLS inspection or evaluate the Server Name Indication (SNI) in the handshake to allow or block specific domain names, regardless of the underlying IP address. By deploying Network Firewall in a VPC with a stateful rule group referencing allowed domains, the engineer can enforce the required domain-based restriction accurately.
- ✗
Configure network ACL outbound rules to allow HTTPS to the IP addresses of the allowed domains.
Why it's wrong here
Network ACLs are stateless layer 3/4 controls that filter by source/destination IP, port, and protocol, and they cannot examine the domain name requested in HTTPS traffic. Additionally, using IP addresses for domain filtering is brittle because domains often resolve to CDN or AWS IPs that can change frequently, causing legitimate traffic to be blocked unexpectedly. Since network ACLs also require separate return-rule configuration for ephemeral ports, this approach is both technically incapable of domain-specific filtering and operationally fragile.
- ✗
Create a VPC endpoint for Amazon S3 and route traffic through it.
Why it's wrong here
A VPC endpoint for Amazon S3 provides private connectivity to the S3 service only; it does not act as a proxy, gateway, or filtering appliance for general internet egress traffic. Even if you force outbound traffic through a gateway endpoint, it cannot inspect or restrict the destination domain of HTTPS requests to arbitrary websites because the endpoint is not positioned or designed for that purpose. Thus, this option fails to provide domain-level control over outbound traffic.
Visual reference
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.