CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud operations team is deploying a three-tier application across two AWS Availability Zones. The database tier must not be reachable from the internet, and the web tier must accept HTTPS from the public. The security architect wants defense in depth at both the subnet and instance levels. Which combination of controls BEST aligns with a layered network security design?
⚠ Common exam trap
The trap here is treating security groups and network ACLs as interchangeable; they operate at different layers and a proper design uses both, with security group references instead of CIDR ranges for internal tiers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place the web tier in a public subnet with a security group allowing 443 from 0.0.0.0/0 and a network ACL allowing 443 inbound; place the database tier in a private subnet with a security group allowing 3306 only from the web tier security group and a network ACL denying all internet CIDR ranges.
A layered VPC design uses network ACLs at the subnet boundary and security groups at the instance level, giving two independent enforcement points. Referencing the web tier's security group as the database source restricts access to authorized instances rather than broad CIDRs. Keeping the database in a private subnet and denying internet CIDRs at the network ACL completes the defense-in-depth model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place both tiers in public subnets and use network ACLs to restrict the database tier to the web tier's CIDR block, with security groups allowing all traffic within the VPC.
Why it's wrong here
Putting the database tier in a public subnet exposes it to internet routing even if network ACLs restrict traffic, which violates the requirement that the database not be reachable from the internet. Allowing all intra-VPC traffic in security groups removes the instance-level control layer. This design weakens both the isolation and the layered control objective.
- ✗
Use AWS WAF in front of the web tier and AWS Shield Advanced for the database tier, with security groups allowing 3306 from the VPC CIDR.
Why it's wrong here
WAF and Shield protect against application-layer and DDoS attacks but do not replace subnet and instance-level network controls. Allowing 3306 from the entire VPC CIDR means any compromised instance in the VPC can reach the database, which is far broader than necessary. This option addresses a different threat model than the layered VPC design requested.
- ✓
Place the web tier in a public subnet with a security group allowing 443 from 0.0.0.0/0 and a network ACL allowing 443 inbound; place the database tier in a private subnet with a security group allowing 3306 only from the web tier security group and a network ACL denying all internet CIDR ranges.
Why this is correct
This design layers stateless network ACLs at the subnet boundary with stateful security groups at the instance level, which is the intended defense-in-depth model in a VPC. The database tier references the web tier's security group rather than a CIDR, so only authorized instances can connect. Denying internet CIDRs at the network ACL adds a second, independent barrier.
- ✗
Place both tiers in private subnets, use a NAT gateway for web tier egress, and rely on security groups alone to control inbound traffic.
Why it's wrong here
Placing the web tier in a private subnet with only a NAT gateway prevents inbound HTTPS from the internet, which contradicts the requirement that the web tier accept public HTTPS. Relying on security groups alone also omits the subnet-level layer the architect explicitly requested. This design mixes up outbound egress with inbound public accessibility.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.