Question 1
Which of the following statements about security groups is incorrect?
Option D is incorrect because Huawei Cloud security-group rules are not limited to literal IP addresses as the source or destination. A security group itself can be referenced in a rule. Huawei's default security group demonstrates this directly: its inbound rule uses the default security group as the source, allowing instances belonging to that security group to communicate with one another. Therefore, another security group can form part of an access-control rule definition.
The other statements reflect the HCIA V3.5 security-group model. Huawei Cloud automatically provides a default security group when required. Its default behavior permits outbound traffic, blocks unsolicited external inbound traffic, and permits communications between instances belonging to the same default group. Option A should therefore be understood in the curriculum's simplified model of allowing outbound and denying external inbound traffic.
Options B and C correctly describe the purpose of security groups. They provide common access-control policies for ECS instances with similar security requirements. Once inbound or outbound rules are configured on the group, those rules govern the instances associated with that group rather than requiring each ECS to be configured independently.
Reference topics: Security Groups; Security Group Sources and Destinations; Default Security Group; ECS Access Control.