Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company has a VPC with public and private subnets. The private subnets contain RDS databases that should not be accessible from the internet. Which configuration ensures that the databases are only accessible from the application servers in the public subnets?

⚠ Common exam trap

Many exam-takers confuse security groups with network ACLs, assuming that a network ACL rule allowing inbound traffic from the public subnet CIDR is sufficient, but they overlook that network ACLs are stateless and do not provide the same granular, instance-level control as security groups, nor do they automatically adapt to changes in application server IPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a security group for the RDS instances that allows inbound traffic from the security group attached to the application servers.

Security groups act as a virtual firewall at the instance level, and you can reference another security group as a source. By creating a security group for the RDS instances that allows inbound traffic from the security group attached to the application servers, you ensure that only those application servers (regardless of their IP addresses) can reach the databases. This approach is more dynamic and secure than using CIDR-based rules, as it automatically accommodates changes in the application servers' IP addresses or scaling events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach an internet gateway to the VPC and route the private subnet's traffic to it.

    Why it's wrong here

    Attaching an internet gateway to the VPC and routing the private subnet's traffic to it would make the private subnet effectively public, exposing the RDS instances to potential inbound internet traffic and defeating the purpose of isolation. An internet gateway only enables bidirectional internet connectivity; it does not establish a controlled path from the application servers in the public subnet to the database in the private subnet. The VPC's local route already allows subnet-to-subnet communication, so the actual missing piece is the security group rule, not an internet gateway.

  • ✗

    Attach a NAT gateway to the private subnet and route traffic through it.

    Why it's wrong here

    A NAT gateway is designed to provide outbound internet access to instances in private subnets, not to accept inbound traffic from other subnets. Placing a NAT gateway in the private subnet would not allow the application servers to initiate connections to RDS, nor would it change the RDS security group that is currently blocking the traffic. The local VPC route already supports bidirectional traffic between the public and private subnets, so the connectivity problem is purely a firewall (security group) issue that a NAT gateway cannot solve.

  • ✗

    Configure a network ACL on the private subnet to allow inbound traffic from the public subnet CIDR.

    Why it's wrong here

    Network ACLs are stateless and operate at the subnet level, so adding an allow rule for the public subnet CIDR would grant access to every host in that subnet, not just the application servers, violating least privilege. You would also need to configure a separate outbound rule to permit ephemeral return traffic, because NACLs do not automatically allow responses. Furthermore, the default network ACL already permits all traffic, so the restrictive component is the RDS security group, which a NACL change would not modify; security groups offer instance-level, stateful control and can reference an application security group for far more precise access.

  • ✓

    Create a security group for the RDS instances that allows inbound traffic from the security group attached to the application servers.

    Why this is correct

    Create a security group for the RDS instances and add an inbound rule that allows the database port from the security group attached to the application servers. Because security groups can reference other security groups as sources, this rule automatically restricts access to only those instances that carry the application security group, regardless of their IP addresses or whether the application tier scales up or down. This stateful, least-privilege approach is the AWS best practice for tiered access within a VPC and directly resolves the connectivity failure without affecting other subnets or relying on broad CIDR ranges.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.