CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud architect is designing a VPC for a three-tier application. The web servers need to be accessible from the internet, while the application servers should only be reachable from the web servers, and the database servers should be isolated from all other traffic except the application servers. Which VPC design best meets these requirements?
⚠ Common exam trap
CCSP often tests the misconception that a single private subnet with security groups is sufficient segmentation, when the exam expects recognition that each trust tier (web, app, DB) requires its own subnet and security group boundary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web servers in a public subnet, app servers in a private subnet, databases in an isolated subnet with appropriate security groups
A three-tier design requires three distinct network zones: a public subnet for internet-facing web servers, a private subnet for application servers reachable only from the web tier, and an isolated (private, no NAT/IGW route) subnet for databases reachable only from the app tier. Security groups enforce the tier-to-tier traffic rules (web SG allows 80/443 from internet; app SG allows app port from web SG; DB SG allows DB port from app SG). This layered segmentation is the canonical defense-in-depth VPC pattern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web servers in a public subnet, app and database servers in a single private subnet
Why it's wrong here
Placing app and database servers in one private subnet lets database traffic reach the app tier directly, violating the isolation requirement. Separate private subnets with security groups scoped per tier are needed; a single subnet is tempting for simplicity but collapses the required traffic boundaries.
- ✗
All servers in a private subnet with a NAT gateway
Why it's wrong here
A NAT gateway only permits outbound-initiated flows, so inbound internet requests to the web tier cannot traverse it, and placing every tier in one private subnet collapses the segmentation the database isolation demands. NAT gateways suit private subnets hosting outbound-only workloads, such as patch or update clients.
- ✗
All servers in a single public subnet with security groups
Why it's wrong here
A single public subnet exposes every instance to inbound internet routing, so application and database tiers become directly reachable, violating the isolation requirement. Security groups filter traffic but cannot remove the public addressing; this design suits flat, single-tier workloads where all hosts legitimately need internet exposure.
- ✓
Web servers in a public subnet, app servers in a private subnet, databases in an isolated subnet with appropriate security groups
Why this is correct
Placing web servers in a public subnet, app servers in a private subnet and databases in an isolated subnet, each governed by security groups, enforces the required traffic flow: internet to web only, web to app, and app to database.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.