Courseiva
easyMultiple Select

CV0-004 Practice Question: Which TWO of the following are best practices…

Which TWO of the following are best practices when configuring a cloud-based virtual private cloud (VPC) for a multi-tier application?

⚠ Common exam trap

CompTIA often tests the misconception that simplicity (placing all instances in one subnet) is a best practice, when in fact proper segmentation is critical for security and compliance in multi-tier architectures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place each application tier in a separate subnet.

Option A is correct because placing each application tier (e.g., web, application, and database tiers) in a separate subnet enables proper network segmentation, allowing you to apply distinct routing, NACLs, and security group rules per tier, which limits lateral movement if one tier is compromised. Option E is correct because restricting SSH (TCP port 22) access to specific management IP addresses via security groups follows the principle of least privilege, preventing brute-force and unauthorized access from the public internet. Options B, C, and D are not best practices: disabling VPC flow logs removes valuable audit and troubleshooting visibility into accepted and rejected traffic; using the default security group for all instances typically allows overly permissive intra-group traffic and violates least privilege; and placing all instances in a single subnet eliminates tier isolation and exposes all components to the same network-level access, increasing blast radius.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Place each application tier in a separate subnet.

    Why this is correct

    Separate subnets per tier let you apply distinct firewall rules and routing between web, application and database layers, enforcing least-privilege segmentation. This directly satisfies the multi-tier isolation requirement rather than leaving all tiers sharing one flat subnet.

  • ✗

    Disable VPC flow logs to reduce costs.

    Why it's wrong here

    Disabling flow logs removes the traffic metadata needed to audit and troubleshoot tier-to-tier communication, weakening detection in a multi-tier VPC. It is tempting because it cuts logging storage costs, and would be reasonable in a non-production sandbox where traffic visibility is not required.

  • ✗

    Use the default security group for all instances.

    Why it's wrong here

    The default security group typically permits broad intra-group traffic, so reusing it for every tier removes the per-tier segmentation a multi-tier VPC requires. It is tempting because it works instantly with no rule authoring, and would suit a single-tier or lab environment where all instances legitimately share one trust level.

  • ✗

    Place all instances in the same subnet for simplicity.

    Why it's wrong here

    A single subnet gives every tier the same routing and network ACL scope, so database and application traffic cannot be isolated by subnet. It is tempting because it minimises routing and CIDR planning, and would be acceptable for a small single-tier deployment where no tier separation is required.

  • ✓

    Restrict SSH access to management IP addresses using security groups.

    Why this is correct

    Restricting SSH to management IP addresses via security groups enforces least-privilege network access on the management plane, satisfying the stem's multi-tier isolation requirement. Security groups act as stateful, instance-level firewalls, so only trusted administrative hosts reach tier instances, shrinking the attack surface exposed to the internet.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.