Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A SysOps Administrator is troubleshooting connectivity issues between two EC2 instances in the same VPC but different subnets. The instances can communicate over private IP addresses when security groups are set to allow all traffic, but fail when security groups are configured with specific rules. The Administrator wants to allow HTTP (port 80) and HTTPS (port 443) traffic from the client instance to the server instance. What security group rules are needed?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add inbound rules on the server to allow HTTP and HTTPS from the client security group.

Security groups are stateful, meaning that if you allow inbound traffic, the response outbound is automatically allowed regardless of outbound rules. Therefore, you only need to add inbound rules on the server instance to allow HTTP and HTTPS traffic from the client security group. Option B is incorrect because no inbound rules are needed on the client. Option C is incorrect because no outbound rules are needed on either instance for this traffic. Option D is incorrect because outbound rules on the server are not required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add inbound rules on the server to allow HTTP and HTTPS from the client security group.

    Why this is correct

    Security groups are stateful, so adding inbound rules on the server to permit HTTP (80) and HTTPS (443) from the client security group is the correct, minimal fix. The inbound rule allows the client's request to reach the server, and because stateful filtering tracks the connection, the server's response is automatically allowed back to the client without any outbound rule on the server. The client security group as the source scopes access precisely to instances with that group, avoiding a 0.0.0.0/0 exposure.

  • ✗

    Add inbound rules on both the client and server.

    Why it's wrong here

    Adding inbound rules on both the client and server is incorrect because the client does not need inbound rules for this traffic. The client is the initiator and sends its HTTP/HTTPS request outbound; the response comes back automatically thanks to statefulness, so inbound on the client is redundant. Inbound rules on the client would only matter if you wanted to allow unsolicited traffic into the client, which is irrelevant to this connectivity problem. The only required change is an inbound rule on the server allowing traffic from the client security group.

  • ✗

    Add outbound rules on both the client and server.

    Why it's wrong here

    Adding outbound rules on both the client and server misdiagnoses which direction the stateful evaluation occurs. The client needs an outbound rule only if its default outbound policy denies all traffic; without that, the request cannot leave the client. The server does not need an outbound rule for the response because security group statefulness automatically permits return traffic for an allowed inbound flow. Adding a server outbound rule is harmless but unnecessary, and adding outbound rules alone will not fix the problem if the server lacks the inbound allow for the request.

  • ✗

    Add inbound rules on the client and outbound rules on the server.

    Why it's wrong here

    This option reverses where the inbound and outbound rules belong. Inbound rules on the client are unnecessary because the client is the source of the request, not the destination, and its responses are covered by stateful return-traffic handling. Outbound rules on the server are also not needed, since the server's response is automatically allowed after an inbound rule permits the matching request. The effective fix is to add an inbound rule on the server (not the client) that allows HTTP/HTTPS from the client security group; adding rules in the wrong direction leaves the server's inbound path blocked, so the request never reaches the service.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.