Best Practices for Security Group References in Multi-Tier Architectures
A security engineer is designing a multi-tier web application on AWS. The web tier must be accessible from the internet, but the application tier should be accessible only from the web tier. The database tier should be accessible only from the application tier. Which combination of security groups provides the MOST secure configuration?
Quick Answer
The correct answer is the configuration that uses security group IDs as references for inter-tier traffic, specifically allowing HTTP/HTTPS from 0.0.0.0/0 on the web SG, HTTP from the web SG ID on the app SG, and MySQL from the app SG ID on the DB SG. This is the most secure approach because security group references are stateful and dynamic—they automatically update as instances are added or removed, unlike static CIDR ranges which can become stale or overly broad. On the AWS Certified Security Specialty SCS-C02 exam, this question tests your understanding of the principle of least privilege and the proper use of security group chaining in multi-tier architectures. A common trap is choosing CIDR-based rules for internal tiers, which reduces security by exposing IP ranges unnecessarily. Remember the memory tip: “Reference the group, not the range—keep your tiers out of danger.”
⚠ Common exam trap
A common mix-up: candidates choose CIDR-based rules (options A or C) because they seem simpler, but they fail to recognize that security group IDs provide a more secure and dynamic way to enforce tier-to-tier access, especially in environments with elastic IPs or auto-scaling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG security group ID. DB SG: allow MySQL from App SG security group ID.
It uses security group IDs as the source for inbound rules, which allows traffic only from instances associated with the specified security group, regardless of their IP addresses. This provides a dynamic and secure way to control traffic between tiers, as security group IDs are resolved at the instance level and automatically adapt to changes in instance membership. By contrast, using CIDR blocks (as in options A and C) is less secure because it relies on static IP ranges that may not accurately reflect the actual instances in the web or app tiers, and option B is overly permissive by allowing all traffic from the web SG.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG CIDR. DB SG: allow MySQL from App SG CIDR.
Why it's wrong here
Using CIDR is less precise; security group references are preferred.
- ✗
Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow all traffic from Web SG. DB SG: allow MySQL from App SG.
Why it's wrong here
Allowing all traffic from Web SG to App SG is overly permissive.
- ✗
Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG security group ID. DB SG: allow MySQL from 10.0.0.0/24.
Why it's wrong here
Using CIDR for DB SG is less secure than using security group ID.
- ✓
Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG security group ID. DB SG: allow MySQL from App SG security group ID.
Why this is correct
Security group references ensure only instances in the web tier can access the app tier, and only instances in the app tier can access the database.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 376 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security engineer is configuring a VPC for a three-tier application. The web tier must be accessible from the internet, the application tier must be accessible only from the web tier, and the database tier must be accessible only from the application tier. Which TWO security group configurations should be used? (Choose TWO.)
medium- A.Allow inbound SSH from 0.0.0.0/0 on the web tier security group.
- ✓ B.Allow inbound HTTP/HTTPS from 0.0.0.0/0 on the web tier security group.
- C.Allow inbound HTTP/HTTPS from the web tier security group on the database tier security group.
- ✓ D.Allow inbound HTTP/HTTPS from the web tier security group on the application tier security group.
- E.Allow inbound HTTP/HTTPS from the internet on the database tier security group.
Why B: The web tier must be accessible from the internet, and allowing inbound HTTP (port 80) and HTTPS (port 443) from 0.0.0.0/0 permits any internet client to reach the web servers. Option D is correct because the application tier must be accessible only from the web tier, and referencing the web tier security group as the source for HTTP/HTTPS traffic ensures that only instances in that security group can initiate connections to the application tier, implementing least-privilege access.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.