Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

Exhibit

Refer to the exhibit.

CloudFormation template snippet:
```yaml
Resources:
  MyEC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: ami-0abcdef1234567890
      InstanceType: t2.micro
      SecurityGroups:
        - !Ref MySecurityGroup
  MySecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow SSH
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 22
          ToPort: 22
          CidrIp: 10.0.0.0/8
```

A SysOps administrator deploys the CloudFormation template shown in the exhibit. The stack creation fails with a security group error. What is the most likely cause?

⚠ Common exam trap

SOA-C02 often tests the EC2-Classic vs VPC property distinction — candidates see 'SecurityGroups' and assume it is valid because it sounds correct, missing that VPC instances require SecurityGroupIds.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The template uses 'SecurityGroups' instead of 'SecurityGroupIds' for a VPC instance.

When launching an EC2 instance into a VPC subnet, CloudFormation's AWS::EC2::Instance resource requires the SecurityGroupIds property (a list of security group IDs), not SecurityGroups (which is only valid for EC2-Classic). Using SecurityGroups with a VPC subnet causes the stack to fail with a security group error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The AMI ID is incorrect.

    Why it's wrong here

    An incorrect AMI ID would produce a distinct failure such as InvalidAMIID.NotFound or InvalidAMIID.Malformed when CloudFormation submits the RunInstances call. The reported issue instead arises during security group parameter validation/association, which happens regardless of AMI identifiers. Since the stack reaches the point of instance network configuration, the AMI ID has already been accepted as valid, so this explanation cannot be the root cause.

  • ✗

    The security group ingress rule uses an invalid CIDR.

    Why it's wrong here

    10.0.0.0/8 is a legitimate RFC 1918 private IPv4 CIDR block, so AWS accepts it in a security group ingress rule without any CIDR parsing error. A truly invalid CIDR—such as 10.0.0.0/33 or 300.1.2.3/24—would trigger a parameter validation failure like InvalidCidrBlock. The observed error is about how the security group is attached to the instance, not about the rule's address range, making this option incorrect.

  • ✓

    The template uses 'SecurityGroups' instead of 'SecurityGroupIds' for a VPC instance.

    Why this is correct

    In CloudFormation's AWS::EC2::Instance resource, the SecurityGroups property accepts security group names and is only supported for EC2-Classic or a default VPC, but when launching an instance into a VPC subnet you must use SecurityGroupIds. Supplying SecurityGroups together with a SubnetId causes the EC2 RunInstances API to receive a group name in a context that requires a group ID, generating a parameter-combination or subnet-not-found error. Changing the template to reference the VPC security group's ID via SecurityGroupIds resolves the deployment failure.

  • ✗

    The security group ingress rule allows SSH from all IPs.

    Why it's wrong here

    A rule allowing SSH from 10.0.0.0/8 only permits connections from within that private RFC 1918 network, not from all IPs, since 0.0.0.0/0 would be required to expose port 22 to the entire internet. While broadly allowing SSH is a poor security practice, CloudFormation does not fail a stack simply because an ingress rule matches a private address range. The reported error is a structural/syntactic problem with the instance resource, so this security policy concern is unrelated to the actual failure.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.