CV0-004 Cloud Architecture and Design Practice Question
A cloud engineer is designing a VPC in AWS for a three-tier web application. The web servers must be accessible from the internet, the application servers should only be accessible from the web servers, and the database servers should only be accessible from the application servers. What is the most secure VPC design?
⚠ Common exam trap
CV0-004 often tests the misconception that security groups alone are sufficient without subnet segmentation, leading candidates to choose a single public subnet design.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Public subnet for web servers, private subnet for application servers, and a separate private subnet for database servers, with proper security group rules
The most secure design places each tier in its own subnet with security groups that restrict traffic: web servers in a public subnet (internet-facing), application servers in a private subnet (only accessible from web servers), and database servers in a separate private subnet (only accessible from application servers). This segmentation limits lateral movement and follows the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Public subnet for web and application servers, private subnet for database servers
Why it's wrong here
Placing application servers in a public subnet gives them routable addresses, so they are reachable from the internet rather than only from the web tier, violating the stated isolation. It is tempting because public subnets simplify outbound access, but application servers belong in a private subnet with security groups referencing the web tier.
- ✗
Single public subnet with all servers placed in it, using security groups to restrict traffic
Why it's wrong here
A single public subnet gives every server, including the database, a route to the internet gateway, so isolation depends solely on security groups rather than network placement. It is tempting because security groups do restrict traffic, but the stem requires the database to be unreachable from outside the application tier.
- ✓
Public subnet for web servers, private subnet for application servers, and a separate private subnet for database servers, with proper security group rules
Why this is correct
Separating web, application and database tiers into public and private subnets, then restricting traffic with security group rules referencing each tier, enforces the required access path. Only web servers are internet-facing, satisfying the constraint that application and database servers remain unreachable directly.
- ✗
Use a single private subnet and a NAT gateway for internet access
Why it's wrong here
A single private subnet with a NAT gateway gives no inbound path for internet users to reach the web servers, so the public tier cannot serve traffic. It is tempting because NAT gateways provide outbound internet access for private resources, which suits backend-only workloads, but here web servers must accept inbound connections.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.