CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud operations team is deploying a web application behind a load balancer in a VPC. The application servers must be reachable only from the load balancer, never directly from the internet. Which configuration achieves this?
⚠ Common exam trap
The trap here is believing that a network ACL or host firewall alone can isolate servers that still reside in a public subnet with an internet route, when subnet placement is the foundational control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place the application servers in a private subnet and attach a security group that allows inbound traffic only from the load balancer's security group.
Private subnets eliminate the internet route, and referencing the load balancer's security group as the allowed source ensures only that balancer can reach the application servers. Public subnets, host firewalls, and elastic IPs all leave direct internet reachability in place, so they fail the isolation requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place the application servers in a public subnet and attach a network ACL that denies inbound traffic from 0.0.0.0/0.
Why it's wrong here
A public subnet has a route to an internet gateway, so the servers could still initiate and receive traffic if the ACL is misconfigured or if egress rules allow responses. Denying inbound from 0.0.0.0/0 at the subnet level is coarse and does not specifically allow the load balancer while blocking others reliably.
- ✗
Keep the application servers in a public subnet but enable a host-based firewall on each instance.
Why it's wrong here
Host firewalls add defense in depth, but the instances still have public IPs and an internet route, so exposure exists if the firewall is misconfigured or bypassed. The requirement is to prevent direct internet reachability, which a public subnet fundamentally undermines.
- ✓
Place the application servers in a private subnet and attach a security group that allows inbound traffic only from the load balancer's security group.
Why this is correct
A private subnet removes the route to an internet gateway, and referencing the load balancer's security group as the source restricts traffic to that balancer. This layered approach ensures no direct internet path and no unauthorized source can reach the application servers.
- ✗
Assign elastic IP addresses to the application servers and restrict access using a VPN.
Why it's wrong here
Elastic IPs make the servers directly addressable from the internet, which contradicts the requirement. A VPN restricts administrative access but does not remove the public reachability of the application servers, so this design fails the isolation objective.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.