After an Amazon VPC instance is launched, can I change the VPC security groups it belongs to?
No. You cannot.
Yes. You can.
Only if you are the root user
Only if the tag “VPC_Change_Group” is true
Security groups are associated with network interfaces. After you launch an instance, you can change the
security groups associated with the instance, which changes the security groups associated with the primary
network interface (eth0).