GCIH Securing Credentials and Data in Cloud Practice Question
When designing a secure cloud database, which configuration best protects against unauthorized data exfiltration if the database instance is misconfigured as public?
⚠ Common exam trap
Candidates rely solely on application-level passwords or database encryption, forgetting that network architecture controls like private subnets provide essential isolation layers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Placing the database in a private subnet with restricted Security Group rules.
Using a Virtual Private Cloud (VPC) and placing the database in private subnets ensures that the database is not routable from the public internet. By combining this with Security Groups that act as stateful firewalls, you create an isolated environment. Even if the database configuration is accidentally set to public, the network layer denies traffic, providing a critical safety net that prevents direct exploitation by external threat actors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Setting a complex root password for the database.
Why it's wrong here
A complex password does not prevent unauthorized network access. If the database is accessible from the internet, an attacker could potentially brute force the password or exploit vulnerabilities in the database service itself. Network-level controls are necessary to prevent the exposure from being reachable in the first place.
- ✓
Placing the database in a private subnet with restricted Security Group rules.
Why this is correct
Private subnets lack a route to an Internet Gateway, effectively isolating the database from the public internet. Restricting Security Group rules to only accept traffic from specific application server subnets ensures that even internal access is highly controlled, significantly reducing the surface area for unauthorized data exfiltration attempts.
- ✗
Enabling database logging for every query.
Why it's wrong here
Logging is an excellent detective control for forensic analysis but does not prevent unauthorized access. An attacker could potentially delete logs or exfiltrate data before an incident response team detects the breach. Prevention, such as network isolation, must take precedence over detective measures in a hardened cloud architecture.
- ✗
Using a public IP address for faster data synchronization.
Why it's wrong here
Using a public IP address exposes the database to the internet, creating a massive security risk. Even if synchronization is faster, the potential for unauthorized access far outweighs the benefit. Secure alternatives like VPC peering or private links provide high-performance connectivity without exposing the database to public network traffic.
Visual reference
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.