A company has a security group rule that allows inbound traffic from 0.0.0.0/0 on port 22. The security engineer wants to restrict SSH access to only the company's public IP range (203.0.113.0/24). What is the correct way to update the security group rule?
Modifying the existing rule's source CIDR from 0.0.0.0/0 to 203.0.113.0/24 is the minimal, precise change: the rule continues to allow TCP/22 only from the company's IP range. Security group rules are stateful and evaluated as a union, so editing the existing rule ensures no separate overly permissive rule remains. This directly satisfies the requirement to allow SSH only from the company IP while preserving connectivity for authorized administrators.
Why this answer
Option B is correct because modifying the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24 directly restricts SSH access to the company's public IP range. Security groups are stateful and allow you to edit rules in place, so this is the simplest and most accurate method.
Exam trap
The trap here is assuming that adding a new rule with a narrower CIDR will override the existing broader rule, but security groups are allow-only and all rules are evaluated together, so the broader rule must be removed or modified.
How to eliminate wrong answers
Option A is wrong because removing the rule without adding a new one would block all SSH access, not just restrict it to the company's range. Option C is wrong because adding a new rule does not automatically deny other traffic; security groups are allow-only, so the existing 0.0.0.0/0 rule would still permit all SSH access. Option D is wrong because outbound rules control outbound traffic, not inbound SSH access; changing outbound rules would not restrict inbound SSH.