Courseiva
Infrastructure Security →mediumMultiple Select

SCS-C02 Infrastructure Security Practice Question

A security engineer is designing a network architecture for a multi-tier application. The web servers must be accessible from the internet, while the application servers must only be accessible from the web servers. Which TWO configurations should be used? (Choose TWO.)

⚠ Common exam trap

Watch out — candidates often confuse network ACLs with security groups, incorrectly assuming that a stateless network ACL with IP-based rules is the correct way to restrict traffic between tiers, when in fact security group references provide a more secure and manageable solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the web servers in a public subnet with a route to an internet gateway.

Option B is correct because placing the web servers in a public subnet with a route to an internet gateway (0.0.0.0/0 → igw-xxxx) is exactly what makes them reachable from the internet, satisfying the requirement that web servers be internet-accessible. Option E is correct because referencing the web servers' security group as the source in the application servers' security group inbound rules enforces that only instances in that web security group can reach the application tier, which is the recommended, identity-based way to restrict access in a multi-tier design. Option A is not needed here: a NAT gateway provides outbound-only internet access for private subnets and does not control inbound access from the web tier, so it does not satisfy the stated requirement. Option C is not the best fit because network ACLs are stateless subnet-level filters based on CIDR ranges; while they can restrict traffic, they are not the mechanism that ties access to the web servers' identity, and the question asks for the configuration that limits application access to the web servers specifically. Option D is wrong because putting the application servers in a public subnet with an internet gateway route would expose them to the internet, directly violating the requirement that they be reachable only from the web servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a NAT gateway in the private subnet for the application servers.

    Why it's wrong here

    A NAT gateway provides outbound-only internet access for private subnets; it does not restrict inbound traffic from the web tier, so application servers stay reachable from other sources. It is tempting because it isolates private subnets from the internet, but that suits egress-only patterns, not tier-to-tier access control.

  • ✓

    Place the web servers in a public subnet with a route to an internet gateway.

    Why this is correct

    A public subnet routes 0.0.0.0/0 to an internet gateway, so web servers can receive inbound internet traffic and respond outbound. This satisfies the requirement that web servers be internet-accessible, while application servers remain in private subnets with no such route.

  • ✗

    Use a network ACL on the application subnet to allow inbound traffic from the web subnet's IP range.

    Why it's wrong here

    Network ACLs are stateless, so return traffic on ephemeral ports must be explicitly permitted; they also filter at subnet level rather than enforcing source security group membership. A security group referencing the web tier's security group is required. NACLs suit coarse subnet-level deny rules, such as blocking a known malicious CIDR range.

  • ✗

    Place the application servers in a public subnet with a route to an internet gateway.

    Why it's wrong here

    A route to an internet gateway makes the application tier directly reachable from the internet, violating the requirement that only web servers may initiate connections to it. Public subnets suit internet-facing load balancers and bastion hosts, not backend tiers that must accept traffic solely from the web tier.

  • ✓

    Configure the application servers' security group to allow traffic only from the web servers' security group.

    Why this is correct

    Security groups support referencing another security group as a source, so the application servers accept traffic only from instances in the web servers' group. This enforces the constraint that application servers be reachable solely from the web tier, regardless of subnet CIDR ranges.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.