Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company runs a three-tier application in a VPC. The web tier is in public subnets behind a Network Load Balancer (NLB). The application tier runs on EC2 instances in private subnets. The database tier is in isolated subnets with no route to a NAT gateway or internet gateway. A SysOps administrator must allow the application tier to initiate connections to the database tier while ensuring the database tier cannot initiate connections to the application tier. Which combination of security group and network ACL configuration should be used?

⚠ Common exam trap

The trap here is assuming that security groups require symmetric inbound and outbound rules for return traffic, when in fact stateful filtering automatically permits return traffic for allowed inbound connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the database security group to allow inbound traffic from the application security group on the database port, and configure the application security group to allow outbound traffic to the database security group on the database port. Leave the database security group's outbound rules empty.

Security groups are stateful and support referencing other security groups as sources or destinations. To allow the application tier to initiate connections to the database tier while preventing the reverse, the database security group should allow inbound traffic from the application security group on the database port. The application security group should allow outbound traffic to the database security group. Because security groups are stateful, return traffic is automatically allowed, and an empty outbound rule set on the database security group prevents the database from initiating connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the application security group to allow inbound traffic from the database security group on the database port, and configure the database security group to allow outbound traffic to the application security group on the application port.

    Why it's wrong here

    This reverses the direction of the required flow. The application tier must initiate connections to the database tier, so the database security group needs an inbound rule allowing the application security group, not the other way around. As written, the application would not be able to connect to the database, and the database would be allowed to initiate connections to the application.

  • ✓

    Configure the database security group to allow inbound traffic from the application security group on the database port, and configure the application security group to allow outbound traffic to the database security group on the database port. Leave the database security group's outbound rules empty.

    Why this is correct

    Security groups are stateful, so return traffic for an allowed inbound connection is automatically permitted regardless of outbound rules. Referencing the application security group as the source restricts access to only those instances. An empty outbound rule set on the database security group prevents the database from initiating outbound connections, satisfying the requirement that the database tier cannot initiate connections to the application tier.

  • ✗

    Configure the database security group to allow inbound traffic from the application subnet CIDR on the database port, and configure the database security group to allow outbound traffic to the application subnet CIDR on the application port.

    Why it's wrong here

    Using subnet CIDR ranges allows any resource in those subnets to connect, which is broader than necessary and violates least privilege. Allowing outbound traffic from the database security group to the application subnet also enables the database tier to initiate connections to the application tier, directly contradicting the stated requirement that the database tier must not initiate connections.

  • ✗

    Configure a network ACL on the database subnet to allow inbound traffic from the application subnet CIDR on the database port, and configure the application subnet's network ACL to allow outbound traffic to the database subnet CIDR on the database port. Leave the database subnet's network ACL outbound rules empty.

    Why it's wrong here

    Network ACLs are stateless, so return traffic from the database to the application would be blocked if the database subnet's outbound rules are empty. This would break the connection. Additionally, network ACLs operate at the subnet level and cannot reference security groups, so this approach lacks the granularity and stateful behavior needed for the scenario.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.