Courseiva
Infrastructure Security →mediumMultiple Select

SCS-C02 Infrastructure Security Practice Question

Exhibit

Which TWO actions should a security engineer take to secure a VPC that contains a public-facing web application?

A security engineer is configuring a VPC for a web application. The VPC has public and private subnets. The web servers are in public subnets and the database servers are in private subnets. The engineer wants to ensure that the database servers are not accessible from the internet. Which two actions should the engineer take?

⚠ Common exam trap

Many exam-takers confuse network ACLs with security groups, thinking a deny-all NACL is sufficient, but they overlook that NACLs are stateless and would block necessary return traffic, whereas security groups are stateful and automatically allow return traffic for permitted inbound connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the route table for the database subnets does not have a default route to an Internet Gateway.

Removing the default route (0.0.0.0/0) to an Internet Gateway (IGW) from the route table associated with the database subnets ensures that traffic from those subnets cannot reach the internet, and the internet cannot initiate connections to instances in those subnets. This is the fundamental network-level isolation required for private subnets in a VPC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place the database instances in a public subnet with a NAT gateway.

    Why it's wrong here

    A NAT gateway is specifically designed to allow outbound internet connectivity from private subnets, not to protect against inbound traffic. If the database instances are placed in a public subnet, that subnet's route table includes a 0.0.0.0/0 route to an internet gateway, which would make the instances reachable from the internet (assuming they have public IPs or are behind a public load balancer). The NAT gateway would not filter or stop this inbound exposure, so this configuration actively increases the attack surface of the database.

  • ✗

    Assign public IP addresses to the database instances.

    Why it's wrong here

    Assigning public IP addresses to the database instances would make them directly addressable from the internet, exposing the data tier to unsolicited inbound connection attempts, such as brute-force attacks or exploitation of unpatched vulnerabilities. In a multi-tier web application architecture, the database should be fully isolated in a private subnet with no public addressing, because internal application servers do not need public IPs to communicate with the database. This approach contradicts the principle of least privilege and is not a valid way to secure the database tier.

  • ✓

    Ensure the route table for the database subnets does not have a default route to an Internet Gateway.

    Why this is correct

    This is correct because omitting a 0.0.0.0/0 route to the internet gateway from the database subnet's route table makes it a private subnet, so unsolicited inbound traffic from the internet has no path to reach the database instances. This routing-layer control ensures that even if a security group rule were overly permissive, the network stack itself would still drop internet-originated packets destined for the database. This is a foundational defense-in-depth measure in VPC design and is required to keep database instances isolated from the public internet.

  • ✓

    Create a security group for the database instances that allows inbound traffic only from the web servers' security group.

    Why this is correct

    This is correct because a security group rule can reference another security group as the source, allowing inbound database traffic only from instances that have the web server security group. This is stateful and operates at the instance level, meaning that even if the web servers' IP addresses change (e.g., during an auto-scaling event), the database remains reachable only by those instances. It is far more precise than using CIDR ranges and pairs effectively with private subnet routing to create a least-privilege access model.

  • ✗

    Configure a network ACL on the database subnets to deny all inbound traffic.

    Why it's wrong here

    Configuring a network ACL to deny all inbound traffic on the database subnets would block every packet entering the subnet, including legitimate traffic from the web application tier. Network ACLs are stateless and are evaluated at the subnet boundary before security groups, so a blanket deny would prevent the database instances from receiving any database requests at all. To allow access, the NACL would need explicit allow rules for the web servers' IP address ranges and matching outbound rules for ephemeral ports, making this option overly restrictive and therefore incorrect.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.