ANS-C01 Network Design Practice Question
A company is designing a network for a three-tier web application. The web tier must be accessible from the internet, the application tier must only be accessible from the web tier, and the database tier must only be accessible from the application tier. Which VPC design meets these requirements with the highest security?
⚠ Common exam trap
Test-takers frequently assume network ACLs are more secure than security groups because they operate at the subnet level, but they overlook the fact that security groups provide stateful, instance-level control that is inherently more secure and easier to manage for isolating application tiers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create public subnets for web tier and private subnets for app and database tiers. Use security groups to allow traffic from web to app and app to database.
It uses separate public subnets for the web tier (with an Internet Gateway for inbound traffic) and private subnets for the application and database tiers, which have no direct route to the internet. Security groups act as stateful virtual firewalls at the instance level, allowing you to precisely control traffic flows: the web tier security group allows inbound HTTP/HTTPS from the internet, the application tier security group allows inbound traffic only from the web tier security group, and the database tier security group allows inbound traffic only from the application tier security group. This layered approach enforces least-privilege access and minimizes the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a single public subnet and use security groups to restrict traffic between instances.
Why it's wrong here
Single subnet does not provide network segmentation.
- ✗
Place all instances in public subnets but assign private IP addresses only.
Why it's wrong here
Public subnets still have route to internet gateway; not recommended for database.
- ✓
Create public subnets for web tier and private subnets for app and database tiers. Use security groups to allow traffic from web to app and app to database.
Why this is correct
Best practices for tiered architecture.
- ✗
Use network ACLs on subnets to restrict traffic instead of security groups.
Why it's wrong here
NACLs are stateless and more difficult to manage for this use case.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on ANS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is designing a network for a multi-tier application. The web tier must be accessible from the internet, the application tier must be accessible only from the web tier, and the database tier must be accessible only from the application tier. Which architecture meets these requirements?
medium- A.Place each tier in a separate subnet and use network ACLs to allow traffic between tiers
- ✓ B.Place each tier in a separate subnet and use security groups to allow traffic between tiers
- C.Place all tiers in the same subnet and use security groups to control traffic
- D.Place all tiers in a public subnet and use a NAT gateway for the application and database tiers
Why B: Security groups act as a stateful virtual firewall at the instance level, allowing you to specify inbound and outbound rules based on source/destination security group IDs. By placing each tier in a separate subnet and referencing the web tier's security group as the source for the application tier's inbound rule, and the application tier's security group as the source for the database tier's inbound rule, you achieve the required least-privilege access without exposing the application or database tiers to the internet.
Variation 2. A company is designing a network for a multi-tier application. The web tier must be accessible from the internet, and the application tier must only be accessible from the web tier. Which architecture should they use?
medium- A.Web servers in private subnets with a NAT Gateway for outbound traffic, and application servers in public subnets
- ✓ B.Web servers in public subnets with an Internet Gateway, and application servers in private subnets with security groups allowing traffic only from the web tier
- C.All servers in a single VPC with VPC Peering to another VPC
- D.Web servers and application servers in public subnets, each with their own security group
Why B: It places the web servers in public subnets with an Internet Gateway (IGW) to allow direct inbound traffic from the internet, while the application servers reside in private subnets with security groups that explicitly permit traffic only from the web tier's security group. This ensures the application tier is not directly reachable from the internet, adhering to the principle of least privilege and defense in depth.
Variation 3. A company is designing a network for a three-tier application that must be PCI DSS compliant. The web tier must be accessible from the internet, the application tier must only be accessible from the web tier, and the database tier must only be accessible from the application tier. All tiers are in the same VPC. What is the MOST secure way to implement this?
easy- A.Use a VPN between the web and application tiers and between application and database tiers.
- B.Place all tiers in the same private subnet and use security groups for isolation.
- ✓ C.Place web tier in public subnets, application and database tiers in private subnets. Use security groups to allow only necessary traffic between tiers.
- D.Place all tiers in public subnets and use network ACLs to restrict traffic.
Why C: The most secure because it places the web tier in public subnets (for internet access) and the application and database tiers in private subnets (no direct internet access). Security groups are used to allow only the necessary traffic between tiers: from web to app on specific ports, and from app to db on specific ports. Security groups are stateful, which simplifies rule management and reduces attack surface. Option A is wrong because a VPN is unnecessary for intra-VPC traffic and adds complexity without improving security. Option B is wrong because placing all tiers in the same private subnet does not provide network isolation between tiers; security groups alone cannot prevent all lateral movement. Option D is wrong because placing all tiers in public subnets exposes the application and database tiers to the internet, and network ACLs are stateless, requiring symmetric rules and increasing management overhead.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.