Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

Network Topology
$ aws ec2 describe-security-groupsgroup-ids sg-12345678Refer to the exhibit.```"SecurityGroups": ["GroupId": "sg-12345678","IpPermissions": ["IpProtocol": "tcp","FromPort": 22,"ToPort": 22,"IpRanges": ["CidrIp": "10.0.0.0/8","Description": "SSH from internal network"},"FromPort": 443,"ToPort": 443,"CidrIp": "0.0.0.0/0","Description": "HTTPS from anywhere"],"IpPermissionsEgress": ["IpProtocol": "-1","FromPort": -1,"ToPort": -1,"CidrIp": "0.0.0.0/0"

A security engineer sees the above security group configuration for an EC2 instance. The instance hosts a web application that should only be accessible from the internal network (10.0.0.0/8) over HTTPS, and SSH should not be open to the internet. What is the security issue with this configuration?

⚠ Common exam trap

The trap here is that candidates focus solely on inbound rules (HTTPS and SSH) and overlook the outbound rule, assuming that stateful security groups automatically handle outbound traffic safely, but AWS explicitly tests that outbound rules must also be restricted to follow least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The outbound rule allows all traffic to all destinations.

The outbound rule allowing all traffic to all destinations (0.0.0.0/0) violates the principle of least privilege. While the inbound rules restrict HTTPS to the internal network (10.0.0.0/8) and SSH is not open to the internet, the outbound rule permits any instance in the security group to initiate connections to any IP address and port, including malicious external hosts. This could allow data exfiltration or outbound attacks, which is a security issue even if inbound access is properly restricted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The outbound rule allows all traffic to all destinations.

    Why this is correct

    The outbound rule is defined as allowing all traffic to 0.0.0.0/0, meaning any instance associated with this security group can initiate connections to any IP address on any port. This violates the principle of least privilege because if an attacker compromises the instance, they could use it as a pivot to exfiltrate sensitive data or launch outbound attacks. Even though inbound HTTPS may also be overly broad, the outbound any-any rule is a critical misconfiguration because it provides no egress filtering or restrictions to required services.

  • ✗

    The inbound HTTPS rule is too permissive.

    Why it's wrong here

    The HTTPS rule does open port 443 to 0.0.0.0/0, which is indeed over-permissive if the service is only meant for internal users. However, the question is asking for the most critical security issue, and open egress is far riskier because it allows any compromised resource to send traffic anywhere. Public HTTPS access is a separate misconfiguration, not the central problem indicated by the security group review.

  • ✗

    The inbound SSH rule is too permissive.

    Why it's wrong here

    The SSH rule's source is an RFC 1918 private range, so it only permits connections from within the internal 10.0.0.0/8 network. This is a sensible restriction for administrative access and does not expose port 22 to the internet. Therefore, this option is incorrect because it falsely claims a security issue when the SSH rule is properly scoped.

  • ✗

    There is no security issue; the configuration is correct.

    Why it's wrong here

    The security group contains an unambiguous egress misconfiguration: an outbound allow-all rule to 0.0.0.0/0. Additionally, the inbound HTTPS rule with source 0.0.0.0/0 may needlessly expose an internal service to the internet. Dismissing the configuration as correct overlooks clear violations of the principle of least privilege.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.