Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is designing a multi-tier web application. The web servers must be accessible from the internet, but the application servers must only be accessible from the web servers. Which AWS feature should be used to meet these requirements?

⚠ Common exam trap

SCS-C02 often tests the confusion between security groups (stateful, instance-level, SG references) and network ACLs (stateless, subnet-level, CIDR-only) — the requirement 'only from the web servers' points to SG referencing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use security groups with rules that allow inbound traffic to the web servers from the internet, and allow inbound traffic to the application servers only from the web server security group.

Security groups are stateful, instance-level virtual firewalls in AWS. By allowing inbound internet traffic to the web server security group and then allowing inbound traffic to the application server security group only from the web server security group (referencing the SG as the source), you enforce that only web servers can reach application servers. This is the standard AWS pattern for tiered isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use security groups with rules that allow inbound traffic to the web servers from the internet, and allow inbound traffic to the application servers only from the web server security group.

    Why this is correct

    Security groups are stateful, instance-level firewalls that allow you to reference another security group as a source. By creating a web server security group that allows inbound TCP/443 and TCP/80 from 0.0.0.0/0, and an application server security group with an inbound rule whose source is the web server security group ID, traffic is permitted only from the specific EC2 instances associated with that web security group. This precisely satisfies the requirement without exposing the application tier directly to the internet, and it automatically accounts for new web instances that join the group.

  • ✗

    Use a VPC peering connection between the web tier and application tier subnets.

    Why it's wrong here

    VPC peering is a networking connection between two separate VPCs that allows traffic routing via private IP addresses. It is not needed here because the web tier and application tier are both part of the same multi-tier application and can reside within a single VPC, using subnets and route tables to segment tiers. VPC peering would only add complexity by introducing a second VPC and requiring route table updates, and it does not by itself enforce any inbound traffic restrictions between the tiers.

  • ✗

    Use network ACLs to allow inbound traffic to the web tier from the internet and to the application tier only from the web tier.

    Why it's wrong here

    Network ACLs are stateless and operate at the subnet level, making them unsuitable for enforcing access specifically from individual web servers to application servers. They would permit traffic from the entire web tier subnet, not just the designated instances, failing to meet the precise requirement. This option is tempting because network ACLs provide a robust, coarse-grained security layer for subnets, effectively blocking broad IP ranges or specific ports as an additional defence mechanism, especially for public-facing subnets.

  • ✗

    Use a VPN connection to isolate the application tier from the web tier.

    Why it's wrong here

    A VPN connection is designed to securely connect an on-premises network or a remote client to an AWS VPC over the internet using IPsec tunnels. It does not isolate application tiers inside a VPC; instead, it would treat the app tier as an external destination and require complex routing, and it would not filter traffic originating from the web tier. Furthermore, a VPN introduces additional latency and operational overhead without providing the granular, security-group-level control needed to allow only web server instances to reach the application servers.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.