Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

Network Topology
$ aws ec2 describe-security-groupsgroup-ids sg-12345678$ aws ec2 describe-network-aclsfilters Name=association.subnet-id"SecurityGroups": ["GroupId": "sg-12345678","IpPermissions": ["IpProtocol": "tcp","FromPort": 22,"ToPort": 22,"IpRanges": [{"CidrIp": "10.0.0.0/8"}]],"IpPermissionsEgress": ["IpProtocol": "-1","IpRanges": [{"CidrIp": "0.0.0.0/0"}]"NetworkAcls": ["NetworkAclId": "acl-12345678","Entries": ["RuleNumber": 100,"Protocol": "6","RuleAction": "allow","Egress": false,"CidrBlock": "0.0.0.0/0","PortRange": {"From": 22, "To": 22}},"RuleNumber": 32767,"Protocol": "-1","RuleAction": "deny","CidrBlock": "0.0.0.0/0"

Refer to the exhibit. A security engineer is unable to SSH into an EC2 instance in subnet-12345678. The instance's security group allows inbound SSH from 10.0.0.0/8, and the instance has a public IP. What is the most likely reason for the failure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The security group inbound rule restricts SSH to the 10.0.0.0/8 range, blocking the engineer's IP.

The network ACL allows inbound SSH from 0.0.0.0/0, but the security group only allows SSH from 10.0.0.0/8. Since the engineer is connecting from an IP outside that range, the security group blocks the connection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The security group egress rule is blocking return traffic.

    Why it's wrong here

    The egress rule cannot be blocking return traffic because it is configured to allow all outbound traffic. Security groups are stateful, so after the inbound SSH connection is accepted, response traffic from the instance to the client's ephemeral port is automatically permitted irrespective of egress rules. Since the egress rule is permissive and stateful tracking covers the reply packets, this option is not the reason for the SSH failure.

  • ✓

    The security group inbound rule restricts SSH to the 10.0.0.0/8 range, blocking the engineer's IP.

    Why this is correct

    The security group inbound rule permits SSH only from sources within the private 10.0.0.0/8 CIDR range, which does not include the security engineer's public IP address. Security groups act as a stateful virtual firewall that filters packets before they reach the instance; if the source IP does not match an allow rule, the packet is silently dropped. This source-restricted SSH rule is the root cause of the connection failure.

  • ✗

    The network ACL's default deny rule (32767) is blocking all inbound traffic.

    Why it's wrong here

    The network ACL's default deny rule numbered 32767 is only a catch-all for traffic that has not already matched an earlier explicit rule. Inbound rule 100 in the exhibit explicitly allows SSH from all source IP addresses, and because network ACL rules are evaluated in ascending order, that allow match is applied before flow ever reaches the default deny. Therefore the catch-all rule is not blocking the inbound SSH connection.

  • ✗

    The network ACL inbound rule for SSH is misconfigured, denying all traffic.

    Why it's wrong here

    This is incorrect because the network ACL inbound rule for SSH is actually configured with an Allow action for all source IPs, not a Deny action. A network ACL is stateless, so the rule simply permits TCP port 22 from any source, which would allow rather than block the engineer's SSH attempt. The SSH failure therefore must be caused by a different layer, namely the security group's source restriction.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.