SCS-C02 Infrastructure Security Practice Question
A security engineer is designing a network architecture for a three-tier web application. The web tier must be accessible from the internet, but the application and database tiers must not. Which VPC configuration should be used?
⚠ Common exam trap
Many exam-takers confuse security groups with subnet routing, assuming that restrictive security groups alone can prevent internet access even when the subnet is public, but the route table's default route to an internet gateway still allows inbound traffic from the internet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place web tier in public subnets, app and database tiers in private subnets.
It places the web tier in public subnets with an internet gateway for direct internet access, while the application and database tiers reside in private subnets with no direct internet route. This ensures that only the web tier is exposed, and the app and database tiers can only be reached through the web tier via internal routing, aligning with the principle of least privilege for a three-tier architecture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place web and app tiers in public subnets, database in private subnet.
Why it's wrong here
Placing the app tier in a public subnet gives it a route to an internet gateway, making the application servers directly reachable from the internet even if security groups restrict some inbound traffic. The app tier does not need public inbound access; it only needs to receive requests from the web tier and may require outbound internet via a NAT gateway for patches or APIs. The database should remain in a private subnet, but the app tier should also be moved to a private subnet to reduce exposure and follow a true three-tier architecture.
- ✓
Place web tier in public subnets, app and database tiers in private subnets.
Why this is correct
This standard three-tier design places only the web tier in public subnets with a route to an internet gateway so it can serve external users. The app and database tiers are in private subnets with no internet gateway route, preventing direct inbound connections from the internet; the app tier receives traffic from the web tier through an internal load balancer or security group rules, and the database is isolated to app-tier-only access. This minimizes the attack surface and is the correct pattern for a public-facing web application.
- ✗
Place all tiers in private subnets and use a VPN for external access.
Why it's wrong here
A private subnet has no route to an internet gateway, so it cannot accept unsolicited public traffic; a VPN only admits remote, pre-authenticated administrative users, not the general web-browsing public that a web tier must serve. Putting all tiers in private subnets and using VPN for external access fails the fundamental requirement of a public-facing web application, and the VPN would become a single control point that does not scale for website visitors. The web tier needs public internet connectivity, so this option is incorrect.
- ✗
Place all tiers in public subnets with security groups restricting access.
Why it's wrong here
Although security groups act as a stateful firewall, placing every tier in a public subnet means each instance has a direct route to an internet gateway, and any security group misconfiguration or overly permissive rule could expose the application or database to the internet. Public subnets should contain only resources that must be reached from the internet, such as the web tier or a load balancer; database and app tiers should reside in private subnets for defense in depth. Relying solely on security groups in public subnets violates the principle of least privilege in network design.
Visual reference
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.