SCS-C02 Infrastructure Security Practice Question
A security engineer is tasked with implementing network segmentation for a multi-tier application. The web tier must be accessible from the internet, but the application tier must only be accessible from the web tier. The database tier must only be accessible from the application tier. All tiers are in the same VPC. Which design meets these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a security group for each tier. Configure inbound rules to allow traffic only from the preceding tier's security group.
Security groups can reference other security groups as sources in inbound rules, allowing granular traffic control between tiers without CIDR blocks. This approach allows the web tier security group to allow inbound from the internet, the app tier security group to allow inbound only from the web tier security group, and the database tier security group to allow inbound only from the app tier security group. Option B is incorrect because IAM policies control user permissions, not network traffic. Option C is incorrect because network ACLs with CIDR blocks are less specific and do not scale well, and placing tiers in separate subnets is not necessary. Option D is incorrect because placing all instances in public subnets unnecessarily exposes them to the internet, increasing security risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a security group for each tier. Configure inbound rules to allow traffic only from the preceding tier's security group.
Why this is correct
Security group chaining gives tier-specific, stateful filtering without hard-coding IP addresses. Define a separate security group for the web, app, and database tiers, then set inbound rules on the app SG that allow traffic from the web SG (on the app port) and on the database SG that allow traffic from the app SG. Because the source is an SG ID, any instance associated with the preceding tier automatically has access, and newly launched instances in that tier are included without updating CIDR rules. This enforces least-privilege east-west traffic isolation.
- ✗
Use a single security group for all instances and use IAM policies to restrict access.
Why it's wrong here
IAM policies are authorization mechanisms for AWS API actions; they have no ability to inspect, filter, or block network packets moving between instances. If all instances share a single security group, then any instance in that group can reach any other on the ports the group allows, so there is no network segmentation between web, app, and database tiers. IAM cannot compensate for a flat network design because it does not sit in the data path of EC2-to-EC2 traffic.
- ✗
Place each tier in separate subnets and use network ACLs with CIDR blocks to allow traffic between tiers.
Why it's wrong here
NACLs are stateless, so filtering traffic between tiers in separate subnets requires writing both inbound and outbound rules for each direction, including rules for ephemeral ports used by return traffic. Using CIDR blocks as sources is also coarser than security-group references: any instance in a referenced subnet is allowed, not just the intended tier's instances, and IP changes require rule updates. Security-group references provide an instance-level, stateful alternative that is simpler to maintain and more precisely scoped.
- ✗
Place all instances in public subnets and restrict access using security groups.
Why it's wrong here
Routing all tiers through a public subnet means every instance is attached to a subnet with a route to an internet gateway, unnecessarily exposing the application and database tiers to inbound internet traffic before the security group is even evaluated. Even with restrictive inbound rules, public subnets expand the attack surface and are contrary to the recommended layered segmentation pattern, where private subnets should host internal workloads and only a load balancer or web tier should be public.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.