Courseiva

GCIH Securing Credentials and Data in Cloud Practice Question

When designing a secure cloud database, which configuration best protects against unauthorized data exfiltration if the database instance is misconfigured as public?

⚠ Common exam trap

Candidates rely solely on application-level passwords or database encryption, forgetting that network architecture controls like private subnets provide essential isolation layers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Placing the database in a private subnet with restricted Security Group rules.

Using a Virtual Private Cloud (VPC) and placing the database in private subnets ensures that the database is not routable from the public internet. By combining this with Security Groups that act as stateful firewalls, you create an isolated environment. Even if the database configuration is accidentally set to public, the network layer denies traffic, providing a critical safety net that prevents direct exploitation by external threat actors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Setting a complex root password for the database.

    Why it's wrong here

    A complex password does not prevent unauthorized network access. If the database is accessible from the internet, an attacker could potentially brute force the password or exploit vulnerabilities in the database service itself. Network-level controls are necessary to prevent the exposure from being reachable in the first place.

  • ✓

    Placing the database in a private subnet with restricted Security Group rules.

    Why this is correct

    Private subnets lack a route to an Internet Gateway, effectively isolating the database from the public internet. Restricting Security Group rules to only accept traffic from specific application server subnets ensures that even internal access is highly controlled, significantly reducing the surface area for unauthorized data exfiltration attempts.

  • ✗

    Enabling database logging for every query.

    Why it's wrong here

    Logging is an excellent detective control for forensic analysis but does not prevent unauthorized access. An attacker could potentially delete logs or exfiltrate data before an incident response team detects the breach. Prevention, such as network isolation, must take precedence over detective measures in a hardened cloud architecture.

  • ✗

    Using a public IP address for faster data synchronization.

    Why it's wrong here

    Using a public IP address exposes the database to the internet, creating a massive security risk. Even if synchronization is faster, the potential for unauthorized access far outweighs the benefit. Secure alternatives like VPC peering or private links provide high-performance connectivity without exposing the database to public network traffic.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.