SCS-C02 Infrastructure Security Practice Question
A company runs a two-tier application in a VPC. The web tier runs on EC2 instances in a public subnet behind an Application Load Balancer. The database tier runs on Amazon RDS for MySQL in two private subnets. A security engineer must harden the database tier so that only the web tier can reach the database on port 3306, and so that the database instances are not reachable from the internet under any circumstances. (Choose two.)
⚠ Common exam trap
The trap here is treating a security group rule as sufficient protection while leaving the database in a subnet that still has a route to an internet gateway or public accessibility enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the RDS subnet group to use only private subnets that have no route to an internet gateway.
Restricting port 3306 by referencing the web tier's security group enforces identity-based access, while keeping the database in private subnets without an internet gateway route removes any possible internet path. Together they satisfy both the least-privilege and the no-internet-exposure requirements without relying on address-based rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach an Elastic IP address to each RDS instance and restrict the security group to the web tier's public addresses.
Why it's wrong here
RDS instances in a private subnet should not carry public addressing, and doing so creates exactly the internet-reachable condition the engineer must prevent. Pinning rules to the web tier's public addresses also breaks when instances are replaced or scaled, and it exposes the database endpoint unnecessarily.
- ✗
Enable public accessibility on the RDS instances and rely on the security group to block unauthorized sources.
Why it's wrong here
Enabling public accessibility assigns a publicly resolvable endpoint that could be reached from outside the VPC if any rule or path allowed it, which violates the requirement that the database never be internet-reachable. Defense should not depend solely on a single rule layer when the exposure itself can be eliminated.
- ✓
Configure the RDS subnet group to use only private subnets that have no route to an internet gateway.
Why this is correct
Placing the database in private subnets with no route to an internet gateway removes any path to or from the internet, which directly satisfies the requirement that the database never be internet-reachable. Route table design, not just security groups, is what guarantees the absence of that path.
- ✓
Attach a security group to the RDS instances that allows inbound TCP 3306 only from the web tier's security group.
Why this is correct
Referencing the web tier's security group as the source restricts database access to instances that carry that group, regardless of their IP addresses. This satisfies the requirement that only the web tier reach port 3306 and avoids hard-coding addresses that change when instances are replaced.
- ✗
Create a network ACL on the private subnets that allows inbound TCP 3306 from 0.0.0.0/0 and denies all other inbound traffic.
Why it's wrong here
Allowing port 3306 from any source contradicts the requirement to restrict access to the web tier and would permit any host that can route to the subnet to attempt a connection. A network ACL on the subnet also cannot express the web tier's identity the way a security group reference can.
Visual reference
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.