SOA-C02 Security and Compliance Practice Question
A SysOps administrator is designing a VPC for a web application that must be secure. Which THREE security measures should the administrator implement? (Choose THREE.)
⚠ Common exam trap
Many candidates confuse network ACLs (stateless, subnet-level) with security groups (stateful, instance-level), or assume that using the default VPC is acceptable for simplicity, when in fact it lacks the granular control needed for a secure architecture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure network ACLs to filter traffic at the subnet level.
Network ACLs (NACLs) are stateless firewalls that operate at the subnet level, providing an additional layer of security by filtering traffic entering and exiting each subnet. By default, NACLs allow all traffic, but you can configure custom rules to explicitly allow or deny traffic based on IP addresses, protocols, and port ranges, which is essential for securing a web application VPC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure network ACLs to filter traffic at the subnet level.
Why this is correct
Network ACLs are a stateless, subnet-level firewall that filters traffic based on numbered rules evaluated in ascending order. Because they are stateless, you must explicitly define both inbound and outbound rules, and responses to allowed inbound traffic require a corresponding outbound rule. NACLs apply uniformly to every instance in the subnet, providing a coarse boundary that can block traffic before it reaches security groups, though they cannot inspect individual instance traffic.
- ✓
Enable VPC Flow Logs to capture traffic information.
Why this is correct
VPC Flow Logs capture metadata about IP traffic going to and from network interfaces in your VPC, such as source/destination IP, port, protocol, and whether the action was accepted or rejected. The logs are published to Amazon CloudWatch Logs or S3, enabling you to audit traffic patterns, diagnose overly permissive or restrictive security group and NACL rules, and support forensic analysis. Flow Logs do not filter or block traffic themselves; they are a visibility tool that complements but never replaces actual security controls.
- ✗
Place all resources in public subnets to simplify access.
Why it's wrong here
Placing all resources in public subnets routes them directly through an Internet Gateway, making them reachable from the internet and dramatically increasing the attack surface. Web application best practice places only load balancers or frontend instances in public subnets, while application servers and databases reside in private subnets with no direct internet exposure. This design prevents a compromise in the data tier from being directly exploitable from the outside and is a fundamental principle of defense-in-depth in a VPC.
- ✓
Use security groups to control inbound and outbound traffic at the instance level.
Why this is correct
Security groups act as a stateful, virtual firewall at the instance or elastic network interface (ENI) level. They support only allow rules by default deny inbound and allow all outbound unless restricted, and because they are stateful, return traffic is automatically permitted regardless of the outbound rule set. Security groups are evaluated as a whole, with no rule ordering, making them ideal for granular, per-instance control based on source security group, CIDR, or port, but they cannot explicitly deny traffic like NACLs can.
- ✗
Use the default VPC for simplicity.
Why it's wrong here
The default VPC is created with public subnets, a route table that sends all traffic to an Internet Gateway, and a default security group that permits unrestricted outbound and all inbound from itself. While convenient for prototyping, it lacks the controlled isolation, private subnets, and custom NACL rules required for production workloads. Using the default VPC without modification can expose resources inadvertently because the default security group and network ACL are permissive by design, leaving you with poor security posture and limited ability to enforce least-privilege access.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.