Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud security engineer is configuring network security for a web application hosted on AWS. The application runs on EC2 instances behind an Application Load Balancer (ALB). The engineer needs to allow HTTP and HTTPS traffic from the internet to the ALB and restrict direct access to the EC2 instances. Which AWS service should be used to control inbound traffic to the ALB?

⚠ Common exam trap

The trap here is assuming that any security service (like WAF or Shield) can replace the fundamental network access control provided by security groups.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security groups

Security groups are stateful virtual firewalls that control inbound and outbound traffic for AWS resources such as ALBs and EC2 instances. They are the correct tool to allow HTTP/HTTPS to an ALB and to restrict EC2 instances to only accept traffic from the ALB. Network ACLs operate at the subnet level and are stateless, AWS WAF is for layer 7 protection, and AWS Shield is for DDoS mitigation, so none of these fulfill the basic network access control requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield is a managed DDoS protection service. It helps protect against volumetric attacks but does not control inbound traffic based on ports and protocols. It is not used to allow or deny specific traffic to an ALB; that is the role of security groups.

  • ✗

    Network ACLs

    Why it's wrong here

    Network ACLs are stateless and operate at the subnet level. They are not attached to individual resources like ALBs. While they can filter traffic, they are not the primary mechanism for controlling access to an ALB, and they lack the stateful inspection and resource-level association that security groups provide.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting. It operates at layer 7 and can be attached to an ALB, but it does not control basic network access (e.g., allowing HTTP/HTTPS). It is used in addition to security groups, not as a replacement.

  • ✓

    Security groups

    Why this is correct

    Security groups act as virtual firewalls for AWS resources, including ALBs and EC2 instances. They control inbound and outbound traffic at the instance level. For an ALB, you attach a security group to allow HTTP/HTTPS from the internet, and you can restrict EC2 instances to only accept traffic from the ALB's security group.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.