SCS-C02 Infrastructure Security Practice Question
Exhibit
Refer to the exhibit.
Exhibit: (CloudFormation snippet)
Resources:
MyEC2Instance:
Type: AWS::EC2::Instance
Properties:
InstanceType: t2.micro
ImageId: ami-0abcdef1234567890
SecurityGroups:
- !Ref MySecurityGroup
MySecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Allow HTTP and SSH
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 0.0.0.0/0
- IpProtocol: tcp
FromPort: 22
ToPort: 22
CidrIp: 10.0.0.0/8Refer to the exhibit. A security engineer is reviewing this CloudFormation template. What security risk is present in this configuration?
⚠ Common exam trap
The trap here is that candidates often focus on the obvious risk of opening SSH to 0.0.0.0/0, but the question tests whether they recognize that an overly broad internal CIDR (10.0.0.0/8) is also a significant security risk, especially when SSH is involved.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSH access is allowed from a large internal CIDR block (10.0.0.0/8) which could expose the instance to unnecessary internal threats.
Allowing SSH (TCP port 22) from the entire 10.0.0.0/8 CIDR block is overly permissive. This range encompasses all RFC 1918 private addresses in the 10.x.x.x space, which could include many internal subnets, VPNs, or peered VPCs that do not require administrative access. Unnecessarily broad internal access increases the attack surface and violates the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The template does not associate the security group with the instance, so the instance has no security group.
Why it's wrong here
This statement is incorrect because the template uses a Ref to the security group resource in the SecurityGroupIds or SecurityGroups property, thereby explicitly associating the group with the instance. In AWS CloudFormation, a security group created as a resource can be referenced by logical ID, so the instance will have that security group attached at launch. The concern is not the association but the overly permissive SSH CIDR.
- ✗
HTTP access is allowed from all IP addresses (0.0.0.0/0) which is a security risk.
Why it's wrong here
Allowing HTTP (port 80) from 0.0.0.0/0 is standard for a public web server and is not considered a security risk, as the service is intended to be openly accessible. Security risks arise when administrative ports like SSH are exposed broadly, so this option does not describe a real vulnerability. The specific issue in the template lies elsewhere.
- ✓
SSH access is allowed from a large internal CIDR block (10.0.0.0/8) which could expose the instance to unnecessary internal threats.
Why this is correct
The 10.0.0.0/8 CIDR block is the entire RFC1918 Class A private address space, covering every possible 10.x.x.x network used by VPCs and internal environments. Opening SSH to this range allows any compromised host in that vast address space to attempt to connect to the instance, which is an unnecessary and overly permissive ingress rule. Best practice is to scope SSH to a specific management CIDR or single IP to maintain least privilege.
- ✗
The template uses SecurityGroups property instead of SecurityGroupIds, which is deprecated.
Why it's wrong here
The SecurityGroups property is not deprecated; it remains valid for referencing security groups by name, while SecurityGroupIds is the recommended property when launching into a VPC to avoid ambiguity. Even if the property choice were deprecated, this would not directly introduce a security vulnerability because the allowed traffic is driven by the security group's rules, not the property name. Thus this is not the correct security concern.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.