CCSP Cloud Security Operations Practice Question
A cloud operations team runs a fleet of Amazon EC2 instances behind an Application Load Balancer. After a recent penetration test, the team must ensure that only HTTP and HTTPS traffic reaches the instances from the load balancer, and that no instance can accept SSH from the internet. The instances currently have a security group named 'web-sg' that allows all inbound traffic from 0.0.0.0/0. Which action should the team take to meet these requirements with the LEAST administrative effort while following AWS best practices?
⚠ Common exam trap
The trap here is assuming that security groups can contain explicit deny rules or that network ACLs can reference security groups, when in fact security groups are allow-only and network ACLs are stateless and cannot reference security groups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the 'web-sg' security group to allow inbound HTTP and HTTPS from the load balancer's security group, and remove all other inbound rules.
Referencing the load balancer's security group in the instance security group is the most precise and least-effort method to restrict inbound traffic to only the load balancer. It leverages AWS security group referencing, which is stateful and supports least privilege without needing CIDR calculations. Removing all other inbound rules ensures no direct internet SSH access, satisfying both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Keep the existing 'web-sg' rules but configure the load balancer to use a target group that only forwards traffic on ports 80 and 443, and enable connection draining.
Why it's wrong here
The load balancer's target group configuration controls outbound traffic to targets but does not restrict inbound traffic to instances. The instances would still accept SSH from the internet because the security group allows all inbound traffic, so this does not meet the requirement of blocking SSH from the internet.
- ✗
Replace the 'web-sg' security group with a new security group that allows inbound HTTP and HTTPS from 0.0.0.0/0, and add a rule to deny SSH from 0.0.0.0/0.
Why it's wrong here
Security groups do not support explicit deny rules; they are allow-only. Adding a deny rule is not possible, and allowing HTTP/HTTPS from 0.0.0.0/0 would permit direct internet access to instances, bypassing the load balancer and violating the requirement that only the load balancer can reach them.
- ✓
Modify the 'web-sg' security group to allow inbound HTTP and HTTPS from the load balancer's security group, and remove all other inbound rules.
Why this is correct
This is correct because referencing the load balancer's security group as the source in the instance security group ensures only traffic from the load balancer is allowed, and removing other rules eliminates internet SSH. It uses security group referencing, which is the AWS-recommended least-privilege approach and requires no changes to the load balancer or instances.
- ✗
Create a new network ACL that allows inbound HTTP and HTTPS from the load balancer subnet and denies all other traffic, then associate it with the instance subnets.
Why it's wrong here
Network ACLs are stateless and operate at the subnet level, so they cannot reference the load balancer's security group. Crafting rules to allow only load balancer traffic by CIDR would be brittle and would not prevent SSH from other sources within allowed CIDR ranges, making this approach less precise and more administrative effort.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.