CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud security engineer is configuring network security for a web application hosted on AWS. The application runs on EC2 instances behind an Application Load Balancer (ALB). The engineer needs to allow HTTP and HTTPS traffic from the internet to the ALB and restrict direct access to the EC2 instances. Which AWS service should be used to control inbound traffic to the ALB?
⚠ Common exam trap
The trap here is assuming that any security service (like WAF or Shield) can replace the fundamental network access control provided by security groups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security groups
Security groups are stateful virtual firewalls that control inbound and outbound traffic for AWS resources such as ALBs and EC2 instances. They are the correct tool to allow HTTP/HTTPS to an ALB and to restrict EC2 instances to only accept traffic from the ALB. Network ACLs operate at the subnet level and are stateless, AWS WAF is for layer 7 protection, and AWS Shield is for DDoS mitigation, so none of these fulfill the basic network access control requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Shield
Why it's wrong here
AWS Shield is a managed DDoS protection service. It helps protect against volumetric attacks but does not control inbound traffic based on ports and protocols. It is not used to allow or deny specific traffic to an ALB; that is the role of security groups.
- ✗
Network ACLs
Why it's wrong here
Network ACLs are stateless and operate at the subnet level. They are not attached to individual resources like ALBs. While they can filter traffic, they are not the primary mechanism for controlling access to an ALB, and they lack the stateful inspection and resource-level association that security groups provide.
- ✗
AWS WAF
Why it's wrong here
AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting. It operates at layer 7 and can be attached to an ALB, but it does not control basic network access (e.g., allowing HTTP/HTTPS). It is used in addition to security groups, not as a replacement.
- ✓
Security groups
Why this is correct
Security groups act as virtual firewalls for AWS resources, including ALBs and EC2 instances. They control inbound and outbound traffic at the instance level. For an ALB, you attach a security group to allow HTTP/HTTPS from the internet, and you can restrict EC2 instances to only accept traffic from the ALB's security group.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.