SCS-C02 Infrastructure Security Practice Question
A company is designing a security group for a web application that must receive HTTPS traffic from the internet and send traffic to a backend database. The backend database is an Amazon RDS MySQL instance. What is the best practice for configuring the security groups?
⚠ Common exam trap
SCS-C02 often tests security group referencing versus CIDR blocks, and candidates frequently choose CIDR-based rules or open database ports to 0.0.0.0/0, missing that security group references provide tighter, identity-based control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web server SG: inbound HTTPS from 0.0.0.0/0. Database SG: inbound MySQL from web server SG.
The best practice is to allow inbound HTTPS from the internet to the web server security group, and then allow inbound MySQL on the database security group referencing the web server security group as the source. This creates a tight, identity-based trust relationship between tiers without hardcoding CIDR ranges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Web server SG: inbound HTTPS from 0.0.0.0/0. Database SG: inbound MySQL from web server SG.
Why this is correct
This configuration is correct because it applies the principle of least privilege: the web server security group only opens HTTPS to the internet, while the database security group restricts MySQL access to only the web server security group via a security group reference. Security group references are dynamic, so any instance attached to the web server SG is automatically allowed, even as the fleet scales, without needing to update CIDR ranges. This also prevents any other source—including other VPCs or subnets—from reaching the database directly.
- ✗
Web server SG: inbound HTTPS from 0.0.0.0/0, outbound to database SG on port 3306. Database SG: inbound MySQL from web server CIDR block.
Why it's wrong here
Although the web server's outbound rule to the database SG on 3306 is directionally appropriate, using the web server's CIDR block on the database inbound rule is a static, brittle approach. If the web server fleet scales or instances receive new private IPs, the CIDR must be manually updated, whereas a security group reference automatically tracks all instances in the group. Moreover, a CIDR rule may unintentionally allow any host within that range to reach the database, rather than just the intended web servers, weakening the security posture.
- ✗
Web server SG: inbound HTTPS from 0.0.0.0/0, outbound all traffic. Database SG: inbound MySQL from 0.0.0.0/0.
Why it's wrong here
This option is fundamentally insecure because it exposes the database directly to the entire internet by allowing MySQL inbound from 0.0.0.0/0, which could allow any malicious host to attempt to connect to the database. Additionally, allowing all outbound traffic from the web server is overly permissive and violates least privilege, as the web server only needs to communicate with the database on port 3306 and respond to clients. This configuration should never be used for a production web application.
- ✗
Web server SG: inbound HTTPS from 0.0.0.0/0, inbound MySQL from database SG. Database SG: outbound MySQL to web server SG.
Why it's wrong here
This configuration reverses the intended traffic flow: the web server should be a MySQL client, not a server, so having an inbound rule on the web server SG for MySQL from the database SG is unnecessary and exposes the web server to database-initiated connections on a port it does not listen on. Furthermore, the database SG's outbound MySQL rule to the web server is redundant because security groups are stateful—allowing inbound MySQL from the web server SG automatically permits return traffic and doesn't need a separate outbound rule. The correct architecture is to allow MySQL inbound on the database SG from the web server SG, with no corresponding inbound on the web server.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.