SCS-C02 Infrastructure Security Practice Question
A security engineer is designing a VPC with private and public subnets. Which TWO actions improve network security? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse security groups (stateful, instance-level) with network ACLs (stateless, subnet-level) and may incorrectly think that a single subnet simplifies security, when in fact it eliminates the network segmentation that is critical for defense in depth.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use security groups to restrict traffic to the database from only the application tier.
Security groups act as a stateful virtual firewall at the instance level, allowing you to restrict inbound traffic to the database instances to only the application tier's security group. This ensures that only traffic originating from the application instances can reach the database, effectively implementing a least-privilege security model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a single subnet for all resources to simplify network rules.
Why it's wrong here
A single subnet collapses the VPC into one flat network segment, eliminating network-level isolation between web, application, and database tiers. With only one subnet, you cannot apply different route tables or network ACLs to enforce boundary controls, so any compromised instance has unrestricted lateral access to the database. Even though security groups still function, the lack of subnet segmentation increases the blast radius of a breach and makes compliance with tiered isolation requirements difficult.
- ✓
Use security groups to restrict traffic to the database from only the application tier.
Why this is correct
Security groups act as a stateful, instance-level firewall that lets you reference another security group as the source. By placing the database in a private subnet and attaching a security group that allows inbound traffic only from the application tier's security group (not from a CIDR), you ensure that only instances with that specific security group can reach the database. This rule automatically accommodates new instances added to the application tier and blocks all other traffic, including from other subnets or external sources, without exposing the database to the internet.
- ✗
Place database instances in a public subnet for easier management.
Why it's wrong here
Placing database instances in a public subnet assigns them public IP addresses and places them in a route table that has a route to an internet gateway, which directly exposes the database to inbound internet traffic. Even if a restrictive security group is applied, the database is still in a network position that increases attack surface and risk of misconfiguration; secure administration should instead be performed through a bastion host or VPN, keeping the database in a private subnet with no direct internet path.
- ✓
Use a NAT gateway in a public subnet for outbound traffic from private subnets.
Why this is correct
A NAT gateway is deployed in a public subnet and uses an Elastic IP to initiate outbound internet connections on behalf of private subnet instances. The private subnet's route table sends 0.0.0.0/0 traffic to the NAT gateway, allowing instances to download patches or access external APIs while preventing any unsolicited inbound connections from the internet. Because NAT gateways are managed by AWS, they automatically scale and provide high availability when deployed in multiple Availability Zones, making them the correct pattern for outbound-only access.
- ✗
Place an internet gateway in a private subnet.
Why it's wrong here
An internet gateway is a horizontally scaled, redundant VPC component that is attached at the VPC level, not deployed inside a subnet. To provide internet access, the internet gateway's ID must appear in the route table of a subnet that is designated as public, but the gateway itself cannot reside in a private subnet. Adding a route to an internet gateway from a private subnet would actually make that subnet public, defeating its isolation, so the correct design is to keep internet gateway routes only in public subnets.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.