Courseiva
Infrastructure Security →mediumMultiple Select

SCS-C02 Infrastructure Security Practice Question

A security engineer is configuring a VPC for a three-tier application. The web tier must be accessible from the internet, the application tier must be accessible only from the web tier, and the database tier must be accessible only from the application tier. Which TWO security group configurations should be used? (Choose TWO.)

⚠ Common exam trap

Many exam-takers confuse the direction of traffic flow and incorrectly apply security group rules to the wrong tier, such as allowing HTTP/HTTPS from the web tier directly to the database tier (Option C) instead of to the application tier, or they mistakenly open unnecessary ports like SSH (Option A) thinking it is needed for management, which violates the principle of least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow inbound HTTP/HTTPS from 0.0.0.0/0 on the web tier security group.

Option B is correct because the web tier is the only tier that must be reachable from the internet, so its security group should permit inbound HTTP (TCP 80) and HTTPS (TCP 443) from 0.0.0.0/0. Option D is correct because the application tier must be accessible only from the web tier, and referencing the web tier's security group as the source in the application tier's inbound rule enforces that tier-to-tier restriction. Option A is wrong because allowing SSH from 0.0.0.0/0 exposes the web tier to unrestricted remote administration and is not required by the scenario. Option C is wrong because the database tier should accept traffic only from the application tier, not directly from the web tier. Option E is wrong because exposing the database tier to inbound HTTP/HTTPS from the internet violates the requirement that it be accessible only from the application tier.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow inbound SSH from 0.0.0.0/0 on the web tier security group.

    Why it's wrong here

    Opening SSH to the internet on any tier is a major security risk because it exposes administrative access to brute-force and credential-stuffing attacks. The web tier security group should only permit web traffic (HTTP/HTTPS) from the internet, while SSH should be restricted to a bastion host or a specific IP/CIDR range. This rule violates the principle of least privilege and should be replaced with a more restrictive source.

  • ✓

    Allow inbound HTTP/HTTPS from 0.0.0.0/0 on the web tier security group.

    Why this is correct

    The web tier is the only component that needs to accept unsolicited traffic from the internet. By allowing HTTP/HTTPS from 0.0.0.0/0, you enable clients to reach the application via the public IP of the load balancer or the web servers. This is a standard and secure configuration because the web tier acts as the entry point that forwards requests to the application tier, and the other tiers remain hidden from direct internet access.

  • ✗

    Allow inbound HTTP/HTTPS from the web tier security group on the database tier security group.

    Why it's wrong here

    The database tier uses its own ports, such as MySQL (3306), PostgreSQL (5432), or others, and it should never receive HTTP/HTTPS traffic. More importantly, the database should only be accessed by the application tier, not directly by the web tier. Permitting HTTP/HTTPS from the web tier on the database security group would break the three-tier architecture and introduce an unnecessary attack vector, as the web tier has no business connecting to the database.

  • ✓

    Allow inbound HTTP/HTTPS from the web tier security group on the application tier security group.

    Why this is correct

    This rule is correct because the application tier needs to handle business logic and must receive forwarded client requests from the web tier. Referencing the web tier security group as the source is a best practice for internal traffic flow, ensuring that only instances in the web tier can communicate with the application tier on the specified ports. It confines communication to the trusted, controlled path defined by the three-tier architecture.

  • ✗

    Allow inbound HTTP/HTTPS from the internet on the database tier security group.

    Why it's wrong here

    A database tier must never be reachable from the internet, regardless of the port. Exposing the database security group to inbound HTTP/HTTPS from the internet would let anyone attempt to access the database, leading to potential data exfiltration or unauthorized modifications. The database should only allow traffic from the application tier’s security group on the appropriate database port, and this rule should never be added.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.