SCS-C02 Infrastructure Security Practice Question
A company has a VPC with a public subnet and a private subnet. An Amazon RDS instance is in the private subnet, and an application server is in the public subnet. The security team needs to allow the application server to connect to the RDS instance on port 3306 (MySQL). Which configuration will meet this requirement securely?
⚠ Common exam trap
Watch out — candidates often confuse security group references with CIDR-based rules, mistakenly thinking that allowing traffic from the subnet CIDR (Option C) is equivalent to allowing traffic from the application server, when in fact it permits any resource in that subnet to connect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add an inbound rule to the RDS security group that allows traffic from the security group of the application server on port 3306.
It uses a security group reference as the source in the inbound rule for the RDS security group. This allows traffic only from the specific application server(s) associated with that security group, regardless of their IP addresses, and automatically scales if the application server is replaced or scaled. This is the most secure and AWS-recommended method for controlling traffic between resources within a VPC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add an inbound rule to the RDS security group that allows traffic from the VPC CIDR on port 3306.
Why it's wrong here
Adding an inbound rule that permits the entire VPC CIDR on port 3306 grants every resource within the VPC—including unrelated compute instances, containers, and future deployments—the ability to connect to the database. This violates the principle of least privilege because it is not scoped to the application server, and it becomes especially risky if the VPC spans multiple subnets or contains other environments that do not require database access.
- ✓
Add an inbound rule to the RDS security group that allows traffic from the security group of the application server on port 3306.
Why this is correct
This is the correct approach: referencing the application server's security group (SG) as the source in the RDS inbound rule permits only traffic originating from network interfaces attached to that specific SG. This pattern—often called SG chaining—is dynamically updated if the instance's private IP changes, is not tied to subnet boundaries, and automatically covers any additional instances that later receive the same SG, making it the most precise and maintainable solution.
- ✗
Add an inbound rule to the RDS security group that allows traffic from the subnet CIDR of the application server on port 3306.
Why it's wrong here
Using the application server's subnet CIDR is an improvement over the VPC CIDR but still over-permissive: any EC2 instance, container, or other resource launched into that subnet can reach the database on port 3306, not just the intended application server. Security group rules are evaluated against the source IP, so this approach cannot distinguish between different instances sharing the same subnet, and it would also include any future resources deployed in that subnet, leaving a broader attack surface than necessary.
- ✗
Add an inbound rule to the RDS security group that allows traffic from 0.0.0.0/0 on port 3306.
Why it's wrong here
Opening port 3306 to 0.0.0.0/0 makes the RDS endpoint reachable from any IP on the Internet, thereby exposing your database credentials to brute-force attacks, SQL injection exploits, and unauthorised data retrieval. Even if the RDS instance is not publicly accessible, such a rule is a severe security misconfiguration and a common source of database breaches, violating the fundamental principle of never exposing a database to the public internet.
Visual reference
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.