Courseiva
Question 1,380 of 1,621
Network ImplementationmediumMultiple ChoiceObjective-mapped

ANS-C01 Network Implementation Practice Question

A company is implementing a network for a three-tier application in a VPC. They need to ensure that the web tier can communicate with the application tier, but the application tier cannot initiate connections to the web tier. Which configuration should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use security groups on the application tier instances to allow inbound from the web tier security group, and do not allow inbound from application tier in the web tier security group

Security groups are stateful and can be configured to allow inbound traffic from the web tier security group to the application tier instances, while the web tier security group only allows inbound from the application tier's security group on specific ports (if needed) and does not allow inbound from the application tier. This prevents the application tier from initiating connections to the web tier. Option A is wrong because network ACLs are stateless and would require explicit inbound and outbound rules to control the direction, but they do not track connection state and are more complex to configure for this requirement. Option B is wrong because a transit gateway is used for connecting multiple VPCs or on-premises networks, not for controlling traffic direction between tiers within the same VPC. Option C is wrong because a reverse proxy is used to forward requests from clients to servers, not to restrict initiation of connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use network ACLs on the application tier subnets to allow inbound from web tier and block outbound to web tier

    Why it's wrong here

    Network ACLs are stateless; blocking outbound would prevent responses.

  • Use a transit gateway with route tables to control traffic flow

    Why it's wrong here

    Transit gateway does not provide stateful filtering.

  • Place a reverse proxy between the tiers

    Why it's wrong here

    Unnecessary; security groups suffice.

  • Use security groups on the application tier instances to allow inbound from the web tier security group, and do not allow inbound from application tier in the web tier security group

    Why this is correct

    Stateful security groups allow responses and block unwanted initiation.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is designing a multi-tier application with web servers in public subnets and database servers in private subnets. The database servers should only be accessible from the web servers. Which AWS feature should be used to enforce this?

easy
  • A.Security groups that reference the web server security group as a source
  • B.VPC endpoints to restrict access to the database servers
  • C.Network ACLs with allow rules for the web server subnet CIDR
  • D.Network ACLs with deny rules for all traffic except from the web server subnet

Why A: Security groups are stateful and act as a virtual firewall for individual instances. By referencing the web server security group as a source in the database security group's inbound rules, you allow traffic only from instances in that security group. This provides granular control at the instance level. Option B is incorrect because VPC endpoints are used to privately connect to AWS services, not to restrict database access. Options C and D are incorrect because network ACLs are stateless and applied at the subnet level, not at the instance level, and they require explicit allow rules for return traffic. Using a NACL with allow rules for the web server subnet CIDR would still allow any instance in that subnet, not just the web servers, and would require managing ephemeral ports.

Last reviewed: Jun 20, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.