SOA-C02 Security and Compliance Practice Question
Exhibit
Refer to the exhibit.
CloudFormation template snippet:
```yaml
Resources:
MyEC2Instance:
Type: AWS::EC2::Instance
Properties:
ImageId: ami-0abcdef1234567890
InstanceType: t2.micro
SecurityGroups:
- !Ref MySecurityGroup
MySecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Allow SSH
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 22
ToPort: 22
CidrIp: 10.0.0.0/8
```A SysOps administrator deploys the CloudFormation template shown in the exhibit. The stack creation fails with a security group error. What is the most likely cause?
⚠ Common exam trap
SOA-C02 often tests the EC2-Classic vs VPC property distinction — candidates see 'SecurityGroups' and assume it is valid because it sounds correct, missing that VPC instances require SecurityGroupIds.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The template uses 'SecurityGroups' instead of 'SecurityGroupIds' for a VPC instance.
When launching an EC2 instance into a VPC subnet, CloudFormation's AWS::EC2::Instance resource requires the SecurityGroupIds property (a list of security group IDs), not SecurityGroups (which is only valid for EC2-Classic). Using SecurityGroups with a VPC subnet causes the stack to fail with a security group error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The AMI ID is incorrect.
Why it's wrong here
An incorrect AMI ID would produce a distinct failure such as InvalidAMIID.NotFound or InvalidAMIID.Malformed when CloudFormation submits the RunInstances call. The reported issue instead arises during security group parameter validation/association, which happens regardless of AMI identifiers. Since the stack reaches the point of instance network configuration, the AMI ID has already been accepted as valid, so this explanation cannot be the root cause.
- ✗
The security group ingress rule uses an invalid CIDR.
Why it's wrong here
10.0.0.0/8 is a legitimate RFC 1918 private IPv4 CIDR block, so AWS accepts it in a security group ingress rule without any CIDR parsing error. A truly invalid CIDR—such as 10.0.0.0/33 or 300.1.2.3/24—would trigger a parameter validation failure like InvalidCidrBlock. The observed error is about how the security group is attached to the instance, not about the rule's address range, making this option incorrect.
- ✓
The template uses 'SecurityGroups' instead of 'SecurityGroupIds' for a VPC instance.
Why this is correct
In CloudFormation's AWS::EC2::Instance resource, the SecurityGroups property accepts security group names and is only supported for EC2-Classic or a default VPC, but when launching an instance into a VPC subnet you must use SecurityGroupIds. Supplying SecurityGroups together with a SubnetId causes the EC2 RunInstances API to receive a group name in a context that requires a group ID, generating a parameter-combination or subnet-not-found error. Changing the template to reference the VPC security group's ID via SecurityGroupIds resolves the deployment failure.
- ✗
The security group ingress rule allows SSH from all IPs.
Why it's wrong here
A rule allowing SSH from 10.0.0.0/8 only permits connections from within that private RFC 1918 network, not from all IPs, since 0.0.0.0/0 would be required to expose port 22 to the entire internet. While broadly allowing SSH is a poor security practice, CloudFormation does not fail a stack simply because an ingress rule matches a private address range. The reported error is a structural/syntactic problem with the instance resource, so this security policy concern is unrelated to the actual failure.
Visual reference
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.