Courseiva
Network DesignhardMultiple SelectObjective-mapped

ANS-C01 Network Design Practice Question

A company has a VPC with a public subnet and a private subnet. The private subnet hosts Amazon RDS instances. The security team wants to ensure that the RDS instances are not accessible from the internet. Which TWO actions should be taken?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Remove the route to an internet gateway from the private subnet's route table.

Options C and D are the correct actions. Removing the route to an internet gateway from the private subnet's route table ensures that the subnet cannot send traffic to or receive traffic from the internet. Launching RDS instances in a private subnet without a public IP address ensures they do not have direct internet connectivity. Option A is not effective because disabling 'Publicly accessible' only prevents RDS from being assigned a public IP address, but if the instance is in a public subnet with a public route, it could still be accessible. Option B is incorrect because a network ACL that denies all inbound traffic from 0.0.0.0/0 would block all inbound traffic, including necessary traffic from within the VPC, and is not a recommended approach. Option E is wrong because configuring a security group to deny all inbound traffic would block all inbound connections, which would prevent legitimate access to RDS from authorized resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable the 'Publicly accessible' option for the RDS instances.

    Why it's wrong here

    This is a good practice, but if the instance has a public IP via a subnet, it could still be accessible. The question asks for VPC-level actions.

  • Create a network ACL that denies all inbound traffic from 0.0.0.0/0.

    Why it's wrong here

    Creating a network ACL that denies all inbound traffic from 0.0.0.0/0 on the private subnet is too restrictive, as it would block legitimate internal traffic from other instances within the VPC to the RDS databases, not just internet access. Network ACLs operate at the subnet level, providing stateless filtering. This option is tempting because 0.0.0.0/0 represents all IP addresses, and denying it seems like a direct way to block internet access. It would be a suitable choice for blocking all inbound internet traffic to a public subnet, or for providing a broad, stateless deny rule for specific unwanted traffic patterns at the subnet boundary.

  • Remove the route to an internet gateway from the private subnet's route table.

    Why this is correct

    Without a route to an internet gateway, traffic cannot reach the internet.

  • Ensure that the RDS instances are launched in a private subnet without a public IP address.

    Why this is correct

    Without a public IP, the instances are not directly reachable from the internet.

  • Configure the security group for the RDS instances to deny all inbound traffic.

    Why it's wrong here

    This would block all inbound traffic, but the question is about internet access; internal traffic may be needed.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has a VPC with a public subnet and a private subnet. The private subnet contains Amazon RDS instances that should only be accessed by EC2 instances in the same VPC. The EC2 instances are in a security group named 'App-SG'. Which configuration will meet the requirement?

easy
  • A.Configure a network ACL on the private subnet to allow inbound traffic from the VPC CIDR.
  • B.Configure a network ACL on the private subnet to allow inbound traffic from the public subnet CIDR.
  • C.Configure a security group on the RDS instances to allow inbound traffic from the 'App-SG' security group.
  • D.Configure a security group on the RDS instances to allow inbound traffic from the VPC CIDR.

Why C: Security groups are stateful and can reference other security groups as a source, allowing traffic from all instances associated with the source security group. By configuring the RDS security group to allow inbound traffic from 'App-SG', only EC2 instances in that group can access the RDS instances, meeting the requirement without exposing the database to the entire VPC CIDR.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.