SCS-C02 Infrastructure Security Practice Question
Network Topology
A security engineer sees the above security group configuration for an EC2 instance. The instance hosts a web application that should only be accessible from the internal network (10.0.0.0/8) over HTTPS, and SSH should not be open to the internet. What is the security issue with this configuration?
⚠ Common exam trap
The trap here is that candidates focus solely on inbound rules (HTTPS and SSH) and overlook the outbound rule, assuming that stateful security groups automatically handle outbound traffic safely, but AWS explicitly tests that outbound rules must also be restricted to follow least privilege.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The outbound rule allows all traffic to all destinations.
The outbound rule allowing all traffic to all destinations (0.0.0.0/0) violates the principle of least privilege. While the inbound rules restrict HTTPS to the internal network (10.0.0.0/8) and SSH is not open to the internet, the outbound rule permits any instance in the security group to initiate connections to any IP address and port, including malicious external hosts. This could allow data exfiltration or outbound attacks, which is a security issue even if inbound access is properly restricted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The outbound rule allows all traffic to all destinations.
Why this is correct
The outbound rule is defined as allowing all traffic to 0.0.0.0/0, meaning any instance associated with this security group can initiate connections to any IP address on any port. This violates the principle of least privilege because if an attacker compromises the instance, they could use it as a pivot to exfiltrate sensitive data or launch outbound attacks. Even though inbound HTTPS may also be overly broad, the outbound any-any rule is a critical misconfiguration because it provides no egress filtering or restrictions to required services.
- ✗
The inbound HTTPS rule is too permissive.
Why it's wrong here
The HTTPS rule does open port 443 to 0.0.0.0/0, which is indeed over-permissive if the service is only meant for internal users. However, the question is asking for the most critical security issue, and open egress is far riskier because it allows any compromised resource to send traffic anywhere. Public HTTPS access is a separate misconfiguration, not the central problem indicated by the security group review.
- ✗
The inbound SSH rule is too permissive.
Why it's wrong here
The SSH rule's source is an RFC 1918 private range, so it only permits connections from within the internal 10.0.0.0/8 network. This is a sensible restriction for administrative access and does not expose port 22 to the internet. Therefore, this option is incorrect because it falsely claims a security issue when the SSH rule is properly scoped.
- ✗
There is no security issue; the configuration is correct.
Why it's wrong here
The security group contains an unambiguous egress misconfiguration: an outbound allow-all rule to 0.0.0.0/0. Additionally, the inbound HTTPS rule with source 0.0.0.0/0 may needlessly expose an internal service to the internet. Dismissing the configuration as correct overlooks clear violations of the principle of least privilege.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.