Courseiva
Security and Compliance →hardMultiple Select

DOP-C02 Security and Compliance Practice Question

Which THREE components are necessary to implement a secure VPC with a public subnet and a private subnet that hosts a database? (Choose THREE.)

⚠ Common exam trap

DOP-C02 often tests whether candidates include unnecessary components like VPN or peering, when the core requirements are IGW, NAT Gateway, and security group scoping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Internet Gateway attached to the VPC.

Option B is correct because an Internet Gateway attached to the VPC is required to give the public subnet's resources (such as a bastion host or load balancer) inbound and outbound connectivity to the internet. Option C is correct because a NAT Gateway placed in the public subnet allows instances in the private subnet to initiate outbound traffic (for patching, updates, etc.) to the internet without being directly reachable from it. Option E is correct because a security group on the database that permits traffic only from the application tier enforces least-privilege, instance-level access control, which is essential for securing the database in the private subnet. Option A is not required because a Site-to-Site VPN is for connecting on-premises networks to AWS, not for building public/private subnet architecture. Option D is not required because VPC peering connects separate VPCs and is unrelated to creating public and private subnets within a single VPC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Site-to-Site VPN connection.

    Why it's wrong here

    A Site-to-Site VPN is not required for constructing a secure, internet-facing VPC; it is an encrypted tunnel that connects an on-premises network to AWS for hybrid cloud architectures. In a standalone VPC with public and private subnets, internet access is provided by an Internet Gateway and a NAT Gateway, and security is enforced by security groups and route tables. Adding a VPN would introduce unnecessary cost and complexity without serving any functional purpose for this basic setup.

  • ✓

    Internet Gateway attached to the VPC.

    Why this is correct

    An Internet Gateway (IGW) is a horizontally scaled, redundant VPC component that provides bidirectional communication between the VPC and the internet. It is attached to the VPC and serves as the target for the 0.0.0.0/0 route in public subnet route tables, enabling resources with public IPs to send and receive internet traffic. Additionally, the IGW is a prerequisite for a NAT Gateway, because the NAT Gateway itself resides in the public subnet and relies on the IGW for outbound internet forwarding. Without an IGW, neither public nor private instances could reach the internet.

  • ✓

    NAT Gateway in the public subnet.

    Why this is correct

    A NAT Gateway is essential for allowing instances in private subnets to initiate outbound connections to the internet—for example, to download software updates or access external APIs—while preventing unsolicited inbound connections from reaching those instances. It is deployed in the public subnet with an Elastic IP address, and the private subnet's route table directs 0.0.0.0/0 to the NAT Gateway ID. This configuration provides a controlled, stateful path for private resources to reach the internet without assigning them public IPs. Removing the NAT Gateway would isolate private instances from external connectivity, thwarting routine administrative tasks.

  • ✗

    VPC Peering connection to a central VPC.

    Why it's wrong here

    VPC Peering is not a required component for this secure VPC architecture; it is a private network connection between two separate VPCs that enables traffic routing using private IPv4 or IPv6 addresses. Peering is useful for multi-VPC designs, such as linking an application VPC to a centralized shared-services VPC, but it does not provide internet access, nor does it enforce traffic security. In a single-VPC layout with application and database tiers, peering is irrelevant and would only add administrative overhead. Furthermore, peering does not support transitive routing, but that nuance does not change the fact that it is unnecessary here.

  • ✓

    Security group for the database allowing traffic only from the application tier.

    Why this is correct

    A security group for the database that allows traffic only from the application tier is a critical component for least-privilege access. By referencing the application tier's security group ID as the source in the inbound rule, the database only accepts traffic from instances that are members of that specific security group, even if the application's IP addresses change over time. Because security groups are stateful, the database's response traffic is automatically allowed, simplifying rule management. This instance-level firewall is necessary to prevent direct external access and to contain security boundaries within the VPC, which network ACLs alone cannot fully achieve.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.