Courseiva
Security and Compliance →easyMultiple Select

SOA-C02 Security and Compliance Practice Question

A SysOps administrator is configuring a new VPC and wants to ensure that only traffic from a specific IP address range can access an EC2 instance via SSH. Which TWO components should be configured? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network ACL (NACL)

To restrict SSH access to a specific IP range, you configure a network ACL at the subnet level and a security group at the instance level. NACLs are stateless and evaluate rules in order; security groups are stateful. Both can allow inbound SSH from the specific IP range. Internet gateway enables internet access but does not filter by IP. Route tables direct traffic but do not filter. VPC endpoint is for private connectivity to AWS services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC endpoint

    Why it's wrong here

    A VPC endpoint, whether interface or Gateway Load Balancer type, creates a private path for traffic to reach a supported AWS service like S3 or DynamoDB without traversing the public internet. It does not inspect or filter traffic for protocols like SSH; it simply bypasses the internet gateway for specific destinations. SSH access to EC2 instances is governed by security groups or network ACLs, not by VPC endpoints.

  • ✓

    Network ACL (NACL)

    Why this is correct

    A network ACL is a stateless virtual firewall at the subnet boundary. It evaluates ingress and egress rules independently, so to allow SSH from a specific CIDR you must add an inbound allow rule and a corresponding outbound rule for ephemeral ports. NACLs can explicitly deny traffic (e.g., block a hostile IP) and are applied to all instances in the subnet, making them an effective subnet-level control for SSH.

  • ✓

    Security group

    Why this is correct

    A security group is a stateful instance-level firewall that filters traffic based on source and destination IPs and ports. You can create an inbound rule allowing SSH (port 22) from a specific CIDR range, and stateful behavior automatically permits the return traffic. Security groups support only allow rules, not explicit deny, and each instance can have multiple security groups for layered control.

  • ✗

    Internet gateway

    Why it's wrong here

    An internet gateway is a horizontally scaled, redundant VPC component that provides a target in route tables for internet-bound traffic. It performs no packet filtering; it merely forwards packets to the public internet when route rules direct them. It does not evaluate source IPs or protocols, so it cannot be used to permit or restrict SSH access.

  • ✗

    Route table

    Why it's wrong here

    A route table controls how outbound traffic is directed by mapping destination CIDR blocks to targets like a NAT gateway, transit gateway, or internet gateway. It is a forwarding mechanism, not a security control; it never inspects or drops traffic based on source IP or port. Thus, it cannot be used to allow or deny SSH traffic.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.