Courseiva
Infrastructure Security →hardMultiple Choice

Best Practices for Security Group References in Multi-Tier Architectures

A security engineer is designing a multi-tier web application on AWS. The web tier must be accessible from the internet, but the application tier should be accessible only from the web tier. The database tier should be accessible only from the application tier. Which combination of security groups provides the MOST secure configuration?

Quick Answer

The correct answer is the configuration that uses security group IDs as references for inter-tier traffic, specifically allowing HTTP/HTTPS from 0.0.0.0/0 on the web SG, HTTP from the web SG ID on the app SG, and MySQL from the app SG ID on the DB SG. This is the most secure approach because security group references are stateful and dynamic—they automatically update as instances are added or removed, unlike static CIDR ranges which can become stale or overly broad. On the AWS Certified Security Specialty SCS-C02 exam, this question tests your understanding of the principle of least privilege and the proper use of security group chaining in multi-tier architectures. A common trap is choosing CIDR-based rules for internal tiers, which reduces security by exposing IP ranges unnecessarily. Remember the memory tip: “Reference the group, not the range—keep your tiers out of danger.”

⚠ Common exam trap

A common mix-up: candidates choose CIDR-based rules (options A or C) because they seem simpler, but they fail to recognize that security group IDs provide a more secure and dynamic way to enforce tier-to-tier access, especially in environments with elastic IPs or auto-scaling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG security group ID. DB SG: allow MySQL from App SG security group ID.

It uses security group IDs as the source for inbound rules, which allows traffic only from instances associated with the specified security group, regardless of their IP addresses. This provides a dynamic and secure way to control traffic between tiers, as security group IDs are resolved at the instance level and automatically adapt to changes in instance membership. By contrast, using CIDR blocks (as in options A and C) is less secure because it relies on static IP ranges that may not accurately reflect the actual instances in the web or app tiers, and option B is overly permissive by allowing all traffic from the web SG.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG CIDR. DB SG: allow MySQL from App SG CIDR.

    Why it's wrong here

    Using CIDR blocks instead of security group references means the App and DB rules trust whole subnets, so any resource in those ranges can reach the tier regardless of role. CIDR rules are tempting when instances sit outside AWS or span accounts, but within one VPC, source security group referencing enforces tier isolation precisely.

  • ✗

    Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow all traffic from Web SG. DB SG: allow MySQL from App SG.

    Why it's wrong here

    Referencing the Web security group as the App rule's source permits traffic from any instance attached to that group, including ones not intended as web tier members, and 'allow all traffic' exceeds the required HTTP scope. Source-group referencing is tempting because it avoids hard-coded CIDRs, but it widens the trust boundary here.

  • ✗

    Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG security group ID. DB SG: allow MySQL from 10.0.0.0/24.

    Why it's wrong here

    Permitting MySQL from the 10.0.0.0/24 CIDR admits any host in that subnet, not solely the application tier, so a compromised instance elsewhere in the range reaches the database. Referencing a peer security group ID is what restricts traffic to actual member instances; CIDR-based rules suit cases where the source is an external network outside AWS security group scope.

  • ✓

    Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG security group ID. DB SG: allow MySQL from App SG security group ID.

    Why this is correct

    Referencing security group IDs as sources enforces tier-to-tier traffic only, so the app tier accepts HTTP solely from the web tier and the database accepts MySQL solely from the app tier. This satisfies the least-privilege constraint without CIDR-based exposure.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security engineer is configuring a VPC for a three-tier application. The web tier must be accessible from the internet, the application tier must be accessible only from the web tier, and the database tier must be accessible only from the application tier. Which TWO security group configurations should be used? (Choose TWO.)

medium
  • A.Allow inbound SSH from 0.0.0.0/0 on the web tier security group.
  • ✓ B.Allow inbound HTTP/HTTPS from 0.0.0.0/0 on the web tier security group.
  • C.Allow inbound HTTP/HTTPS from the web tier security group on the database tier security group.
  • ✓ D.Allow inbound HTTP/HTTPS from the web tier security group on the application tier security group.
  • E.Allow inbound HTTP/HTTPS from the internet on the database tier security group.

Why B: Option B is correct because the web tier is the only tier that must be reachable from the internet, so its security group should permit inbound HTTP (TCP 80) and HTTPS (TCP 443) from 0.0.0.0/0. Option D is correct because the application tier must be accessible only from the web tier, and referencing the web tier's security group as the source in the application tier's inbound rule enforces that tier-to-tier restriction. Option A is wrong because allowing SSH from 0.0.0.0/0 exposes the web tier to unrestricted remote administration and is not required by the scenario. Option C is wrong because the database tier should accept traffic only from the application tier, not directly from the web tier. Option E is wrong because exposing the database tier to inbound HTTP/HTTPS from the internet violates the requirement that it be accessible only from the application tier.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.