SCS-C02 Infrastructure Security Practice Question
A company is deploying a multi-tier web application across multiple Availability Zones. The application includes a web tier, application tier, and database tier. The security team requires that the web tier can communicate with the application tier only on port 8080, and the application tier can communicate with the database tier only on port 3306. Which security group configuration should be used?
⚠ Common exam trap
SCS-C02 often tests whether candidates know security groups can reference other security groups, so they default to CIDR-based rules and lose least-privilege points.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the application tier security group, allow inbound from the web tier security group on port 8080. In the database tier security group, allow inbound from the application tier security group on port 3306.
Referencing security groups as sources (security group referencing) is the AWS-recommended, least-privilege approach for tiered applications. The application tier SG allows inbound on 8080 only from the web tier SG, and the database tier SG allows inbound on 3306 only from the application tier SG. This ensures traffic is permitted based on the identity of the source instances, not on IP ranges, and it scales automatically as instances are added or removed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
In the application tier security group, allow inbound from the web tier security group on port 8080. In the database tier security group, allow inbound from the application tier security group on port 3306.
Why this is correct
This is correct because security group references create a logical firewall between tiers that is independent of IP addresses. The application tier security group only accepts HTTP traffic originating from resources that are members of the web tier security group, and the database tier security group only accepts MySQL traffic from members of the application tier security group. AWS resolves the referenced security group to the private IPs of its associated instances at the time the traffic is evaluated, so scaling events and IP changes do not require rule updates.
- ✗
In the database tier security group, allow inbound from the application tier's CIDR block on port 3306.
Why it's wrong here
Using the CIDR block of the application tier is less specific because it permits any resource whose IP falls within that range to reach port 3306, not solely the application tier instances. If the application tier spans multiple subnets, this approach requires separate rules or a broadened CIDR, which increases the attack surface; conversely, if an instance's IP changes through auto scaling, the rule may stop matching. A security group reference would restrict access to exactly the intended instances and automatically accommodate IP changes.
- ✗
In the application tier security group, allow inbound from the web tier's CIDR block on port 8080.
Why it's wrong here
Referencing the web tier's CIDR rather than its security group allows any network resource inside that CIDR, such as a compromised instance in a different tier or an unrelated workload, to send traffic to port 8080 on the application tier. Security groups are not constrained to subnets, so the web tier instances may not even be the only owners of that IP range. Using the web tier security group ID ensures only instances that actually belong to the web tier are treated as valid sources.
- ✗
In the web tier security group, allow outbound to 0.0.0.0/0 on port 8080.
Why it's wrong here
This egress rule is incorrect because it permits the web tier instances to initiate outbound connections to any public or private IP on TCP 8080, which is unnecessary and overly permissive for a web application. For external users to reach the web tier, the security group needs an inbound rule allowing HTTP/HTTPS from 0.0.0.0/0; return traffic is handled automatically because security groups are stateful, so an outbound rule is not what enables browsing. Restricting outbound to known destinations or using no such broad allow better follows a least-privilege security posture.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.