CV0-004 Cloud Architecture and Design Practice Question
A financial services firm is moving a regulated trading application to a public cloud. The security team must prove that data is encrypted in transit between the application tier and the database tier, and that only the application tier can reach the database port. Which two controls should the cloud architect implement? (Choose two.)
⚠ Common exam trap
The trap here is accepting encryption at rest as proof of encryption in transit, when the two protect entirely different states of the data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the database to accept connections only over TLS and require certificate validation from the application tier.
Encryption in transit and least-privilege reachability are distinct controls that must be paired. Requiring TLS with certificate validation on the database listener proves the channel is cryptographically protected, and a security group rule that names the application tier's security group as the only permitted source enforces role-based access to the database port. Encryption at rest, private subnets with NAT, and subnet-level ACLs address other concerns and do not satisfy either requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a network ACL on the database subnet that denies all traffic except the application subnet CIDR range.
Why it's wrong here
A network ACL filters at the subnet boundary using CIDR ranges, but it is stateless and coarse, and any host placed in the application subnet later would be permitted regardless of role. It also provides no encryption, so the evidence of an encrypted channel between tiers would still be missing, leaving the primary requirement unfulfilled.
- ✓
Configure the database to accept connections only over TLS and require certificate validation from the application tier.
Why this is correct
Enforcing TLS on the database listener with mandatory certificate validation ensures the channel between application and database is encrypted and that the application verifies the database identity, preventing interception or spoofing. This directly produces the cryptographic evidence auditors require for encryption in transit between the two tiers.
- ✗
Deploy the database into a private subnet with a NAT gateway so it can initiate outbound updates.
Why it's wrong here
Placing the database in a private subnet removes direct internet exposure, but a NAT gateway governs outbound traffic only and does not encrypt inbound client connections nor limit which tier may connect. The database port would still be reachable by any host with routing and a permissive security group, so neither stated requirement is satisfied.
- ✓
Attach a security group to the database that allows the database port only from the application tier's security group.
Why this is correct
Referencing the application tier's security group as the source makes the rule identity-based rather than IP-based, so only instances in that group can open the database port. This satisfies the requirement that only the application tier reach the database, and it keeps working as application instances scale or change addresses.
- ✗
Enable encryption at rest on the database volume using a customer-managed key stored in the cloud provider's key management service.
Why it's wrong here
Encryption at rest protects data on the storage media but says nothing about the network path between tiers, so it cannot demonstrate encryption in transit. It also does not restrict which hosts may open the database port, leaving the second requirement unmet despite being a valuable control for a different threat.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.