Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud architect is designing a VPC for a three-tier application. The web servers need to be accessible from the internet, while the application servers should only be reachable from the web servers, and the database servers should be isolated from all other traffic except the application servers. Which VPC design best meets these requirements?

⚠ Common exam trap

CCSP often tests the misconception that a single private subnet with security groups is sufficient segmentation, when the exam expects recognition that each trust tier (web, app, DB) requires its own subnet and security group boundary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web servers in a public subnet, app servers in a private subnet, databases in an isolated subnet with appropriate security groups

A three-tier design requires three distinct network zones: a public subnet for internet-facing web servers, a private subnet for application servers reachable only from the web tier, and an isolated (private, no NAT/IGW route) subnet for databases reachable only from the app tier. Security groups enforce the tier-to-tier traffic rules (web SG allows 80/443 from internet; app SG allows app port from web SG; DB SG allows DB port from app SG). This layered segmentation is the canonical defense-in-depth VPC pattern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Web servers in a public subnet, app and database servers in a single private subnet

    Why it's wrong here

    Placing app and database servers in one private subnet lets database traffic reach the app tier directly, violating the isolation requirement. Separate private subnets with security groups scoped per tier are needed; a single subnet is tempting for simplicity but collapses the required traffic boundaries.

  • ✗

    All servers in a private subnet with a NAT gateway

    Why it's wrong here

    A NAT gateway only permits outbound-initiated flows, so inbound internet requests to the web tier cannot traverse it, and placing every tier in one private subnet collapses the segmentation the database isolation demands. NAT gateways suit private subnets hosting outbound-only workloads, such as patch or update clients.

  • ✗

    All servers in a single public subnet with security groups

    Why it's wrong here

    A single public subnet exposes every instance to inbound internet routing, so application and database tiers become directly reachable, violating the isolation requirement. Security groups filter traffic but cannot remove the public addressing; this design suits flat, single-tier workloads where all hosts legitimately need internet exposure.

  • ✓

    Web servers in a public subnet, app servers in a private subnet, databases in an isolated subnet with appropriate security groups

    Why this is correct

    Placing web servers in a public subnet, app servers in a private subnet and databases in an isolated subnet, each governed by security groups, enforces the required traffic flow: internet to web only, web to app, and app to database.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.