nerdexam
Amazon

SOA-C02 · Question #50

An Amazon EC2 instance is in a private subnet. To SSH to the instance, it is required to use a bastion host that has an IP address of 10.0.0.5. SSH logs on the EC2 instance in the private subnet show

Sign in or unlock SOA-C02 to reveal the answer and full explanation for question #50. The question stem and answer options stay visible for context.

Submitted by rohit_dlh· Mar 30, 2026Security and Compliance

Question

An Amazon EC2 instance is in a private subnet. To SSH to the instance, it is required to use a bastion host that has an IP address of 10.0.0.5. SSH logs on the EC2 instance in the private subnet show that connections are being made over SSH from several other IP addresses. The EC2 instance currently has the following inbound security group rules applied:

Protocol: TCP Port: 22 Source: 10.0.0.5/32 Protocol: TCP Port: 22 Source: sg-xxxxxxxx Protocol: TCP Port: 389 Source: 0.0.0.0/0 What is the MOST likely reason that another IP addresses is able to SSH to the EC2 instance?

Options

  • AThe rule with 0.0.0.0/0 means SSH is open for any client to connect
  • BThe rule with /32 is not limiting to a single IP address
  • CAny instance belonging to sg-xxxxxxxx is allowed to connect
  • DThere is an outbound rule allowing SSH traffic

Unlock SOA-C02 to see the answer

You've previewed enough free SOA-C02 questions. Unlock SOA-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Security Groups#EC2 Networking#Access Control#Network Security
Full SOA-C02 Practice