Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company is deploying a multi-tier application on AWS. The web tier must be publicly accessible, but the application tier must only be accessible from the web tier. The database tier should not be accessible from the internet at all. Which combination of security groups and network ACLs should be used?

⚠ Common exam trap

DOP-C02 often tests the difference between security groups and network ACLs; candidates may choose network ACLs for instance-level control or forget that security groups can reference other security groups.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use security groups: allow 0.0.0.0/0 on port 80/443 to web tier, allow web tier security group to app tier, allow app tier security group to database tier.

The correct approach is to use security groups that enforce least privilege: allow public access to the web tier on ports 80/443, allow the web tier security group to access the app tier, and allow the app tier security group to access the database tier. This creates a chain of trust where each tier only accepts traffic from the previous tier.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use security groups: allow 0.0.0.0/0 on all ports to web tier, allow all traffic between all instances.

    Why it's wrong here

    Opening the web tier to 0.0.0.0/0 on all ports is a severe security risk because it exposes management services such as SSH (port 22) and RDP (port 3389) to the entire internet, greatly increasing the attack surface. Simultaneously, allowing all traffic between all instances eliminates network segmentation and enables unrestricted lateral movement: if a single web server is compromised, an attacker can trivially reach the app and database tiers on any port or protocol. This violates the principle of least privilege and ignores AWS's security model, where security groups should be scoped to the minimal set of ports and sources required for the application to function.

  • ✗

    Place all instances in the same security group with inbound rules allowing only ports 80/443 from 0.0.0.0/0.

    Why it's wrong here

    Assigning every instance to a single shared security group and allowing inbound 0.0.0.0/0 on ports 80/443 means that the same rule applies to every instance, including app and database servers. Even if those servers are not actively listening, the security group boundary is effectively flat and offers no tier-to-tier isolation; an attacker who gains access to the network can attempt to reach app or database instances directly from the internet because the rule permits all IPs on those ports. The correct pattern is to create tier-specific security groups and reference the upstream tier's security group as the source, thereby restricting inbound traffic at the instance level rather than relying on a single, overly permissive group.

  • ✓

    Use security groups: allow 0.0.0.0/0 on port 80/443 to web tier, allow web tier security group to app tier, allow app tier security group to database tier.

    Why this is correct

    This is the correct multi-tier security group design because it enforces least privilege with instance-level granularity. The web tier security group allows only HTTP/S from the internet, the app security group allows traffic only from the web security group (not from any IP or CIDR), and the database security group allows only from the app security group. Using security group references instead of CIDR blocks means that any instance bearing the web SG is automatically allowed to reach the app tier, which makes scaling and instance replacement seamless without updating rules. This approach is stateful, so responses are automatically allowed, and it is far more secure than subnet-level NACL rules, which are stateless and cannot distinguish between instances within the same subnet.

  • ✗

    Use network ACLs: allow 0.0.0.0/0 on port 80/443 to web subnet, allow web subnet to app subnet, allow app subnet to database subnet.

    Why it's wrong here

    Network ACLs operate at the subnet level and are stateless, meaning they cannot provide the instance-level granularity required to ensure the application tier is *only* accessible from specific web tier instances, rather than any instance within the web subnet. This option is tempting because network ACLs are effective for broad, coarse-grained filtering at the subnet boundary, serving as a valuable second layer of defence or for blocking known malicious IP ranges from an entire subnet.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.