Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is designing a network architecture for a multi-tier web application. The application consists of a public-facing ALB, web servers in private subnets, and an RDS database in isolated subnets. The security team requires that the web servers have no direct internet access. Which VPC configuration meets this requirement?

⚠ Common exam trap

Many exam-takers confuse 'no direct internet access' with 'no internet access at all,' leading them to choose isolated subnets (Option B) instead of recognizing that private subnets with a NAT Gateway allow outbound-only internet access, which satisfies the requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Private subnets with a NAT Gateway in a public subnet.

Placing web servers in private subnets with a NAT Gateway in a public subnet allows them to initiate outbound connections to the internet (e.g., for software updates) while preventing any inbound internet traffic from reaching them directly. The NAT Gateway translates private IPs to the public IP of the gateway, and the private subnets' route table points 0.0.0.0/0 to the NAT Gateway, not an Internet Gateway, ensuring no direct internet access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Public subnets with an Internet Gateway.

    Why it's wrong here

    Placing all tiers in public subnets with an Internet Gateway (IGW) exposes instances to inbound traffic from anywhere on the internet. An IGW provides bidirectional routing, so even if security groups restrict ports, the instances remain directly reachable from public IPs. This violates the least-privilege principle for a multi-tier design, as application and database tiers should never have unmediated inbound internet access.

  • ✗

    Isolated subnets with no route to the internet.

    Why it's wrong here

    Isolated subnets with no route to the internet completely block outbound connectivity, preventing instances from reaching patch repositories, OS update servers, or external APIs. While this is appropriate for air-gapped workloads, it fails for a multi-tier architecture that requires routine egress for maintenance and integration. The absence of any NAT device or internet gateway means traffic cannot leave the VPC, making these subnets operationally restrictive.

  • ✓

    Private subnets with a NAT Gateway in a public subnet.

    Why this is correct

    Private subnets with a NAT Gateway in a public subnet provide a controlled outbound-only internet path. The private subnets' route table sends 0.0.0.0/0 to the NAT Gateway, which holds an Elastic IP and translates traffic, while inbound connections from the internet are still impossible. This allows instances to fetch updates and call external services without being directly exposed, making it the recommended multi-tier architecture pattern.

  • ✗

    Private subnets with a VPN connection to the corporate network.

    Why it's wrong here

    Private subnets with a VPN connection to the corporate network only establish private connectivity to on-premises systems; they do not provide any internet egress. A Site-to-Site VPN or Direct Connect routes traffic between the VPC and corporate data center, not to the public internet. For any tier needing internet access, this configuration would still require an internet gateway or NAT gateway, so it does not solve the outbound connectivity requirement.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.