Courseiva

CV0-004 Cloud Architecture and Design Practice Question

A financial services firm is moving a regulated trading application to a public cloud. The security team must prove that data is encrypted in transit between the application tier and the database tier, and that only the application tier can reach the database port. Which two controls should the cloud architect implement? (Choose two.)

⚠ Common exam trap

The trap here is accepting encryption at rest as proof of encryption in transit, when the two protect entirely different states of the data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the database to accept connections only over TLS and require certificate validation from the application tier.

Encryption in transit and least-privilege reachability are distinct controls that must be paired. Requiring TLS with certificate validation on the database listener proves the channel is cryptographically protected, and a security group rule that names the application tier's security group as the only permitted source enforces role-based access to the database port. Encryption at rest, private subnets with NAT, and subnet-level ACLs address other concerns and do not satisfy either requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a network ACL on the database subnet that denies all traffic except the application subnet CIDR range.

    Why it's wrong here

    A network ACL filters at the subnet boundary using CIDR ranges, but it is stateless and coarse, and any host placed in the application subnet later would be permitted regardless of role. It also provides no encryption, so the evidence of an encrypted channel between tiers would still be missing, leaving the primary requirement unfulfilled.

  • ✓

    Configure the database to accept connections only over TLS and require certificate validation from the application tier.

    Why this is correct

    Enforcing TLS on the database listener with mandatory certificate validation ensures the channel between application and database is encrypted and that the application verifies the database identity, preventing interception or spoofing. This directly produces the cryptographic evidence auditors require for encryption in transit between the two tiers.

  • ✗

    Deploy the database into a private subnet with a NAT gateway so it can initiate outbound updates.

    Why it's wrong here

    Placing the database in a private subnet removes direct internet exposure, but a NAT gateway governs outbound traffic only and does not encrypt inbound client connections nor limit which tier may connect. The database port would still be reachable by any host with routing and a permissive security group, so neither stated requirement is satisfied.

  • ✓

    Attach a security group to the database that allows the database port only from the application tier's security group.

    Why this is correct

    Referencing the application tier's security group as the source makes the rule identity-based rather than IP-based, so only instances in that group can open the database port. This satisfies the requirement that only the application tier reach the database, and it keeps working as application instances scale or change addresses.

  • ✗

    Enable encryption at rest on the database volume using a customer-managed key stored in the cloud provider's key management service.

    Why it's wrong here

    Encryption at rest protects data on the storage media but says nothing about the network path between tiers, so it cannot demonstrate encryption in transit. It also does not restrict which hosts may open the database port, leaving the second requirement unmet despite being a valuable control for a different threat.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.