Courseiva
Design for New Solutions →easyMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A company is designing a new microservices architecture on Amazon ECS with Fargate. Each microservice must be isolated and able to communicate with others only through defined APIs. Which solution provides the BEST isolation and security?

⚠ Common exam trap

The SAP-C02 exam often tests the misconception that network-level controls (security groups, VPC peering) are sufficient for microservice isolation, but the exam requires understanding that application-layer service mesh (like App Mesh) provides the necessary API-level security and observability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS App Mesh with Envoy sidecars to control traffic between services.

AWS App Mesh with Envoy sidecars provides service-level traffic control, encryption, and observability without modifying application code. It enforces fine-grained routing and security policies (e.g., mTLS, retries, timeouts) between microservices, ensuring isolation and that communication only occurs through defined APIs. This aligns with the microservices principle of strict API boundaries and defense in depth.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS App Mesh with Envoy sidecars to control traffic between services.

    Why this is correct

    AWS App Mesh injects Envoy sidecar proxies into each Fargate task, giving per-service identity, mutual TLS, and explicit traffic routing so services communicate only through defined APIs. This satisfies the isolation and API-only communication requirements better than security groups alone.

  • ✗

    Place all microservices in the same security group and allow all traffic.

    Why it's wrong here

    A shared security group permitting all traffic removes the per-microservice network boundary the stem requires, so any task can reach any other directly. Security groups are the right tool for restricting traffic to specific ports and sources, but only when each microservice has its own group referencing the others' groups.

  • ✗

    Use an Application Load Balancer per microservice with listener rules.

    Why it's wrong here

    An ALB per microservice provides ingress routing and TLS termination, not task-to-task isolation; tasks in the same subnet and security group still reach each other directly. ALBs are correct when exposing HTTP services to external or cross-service clients, not for enforcing east-west API-only communication.

  • ✗

    Use VPC peering between each microservice's VPC.

    Why it's wrong here

    VPC peering connects whole VPCs with full routable access, so it cannot restrict traffic to defined APIs and adds no isolation between tasks. Peering is correct for joining separate VPCs that must exchange broad traffic, such as shared services across accounts, not for microservice-level API boundaries.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.