CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud provider offers a virtual private cloud (VPC) with a subnet that hosts a database. A security architect must ensure that only instances in a specific application security group can connect to the database on port 3306, and that no other traffic from the internet or other subnets can reach it. The architect is configuring security groups and network ACLs. Which combination of rules BEST achieves this?
⚠ Common exam trap
The trap here is assuming network ACLs can reference security group IDs or that subnet CIDR is equivalent to security group membership, when only security groups support security group references and stateful evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the database security group to allow inbound TCP 3306 from the application security group ID, and leave the network ACL at its default allow-all state.
Security groups are stateful and can reference other security groups as sources, which is the most precise way to allow only instances with a specific application security group to reach the database. Network ACLs are stateless and subnet-level; they cannot reference security group IDs and should generally be left at default allow unless additional subnet-level controls are needed. Allowing the application security group ID on the database security group meets the requirement exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the database security group to allow inbound TCP 3306 from 0.0.0.0/0, and configure the network ACL to deny all traffic except from the application subnet CIDR.
Why it's wrong here
Allowing 0.0.0.0/0 on the database security group exposes the database to the internet, even if the NACL restricts subnet traffic. NACLs are stateless and can be bypassed if rules are misordered, and they cannot reference security groups. This violates the requirement that only the application security group can connect.
- ✗
Configure the database security group to allow inbound TCP 3306 from the application subnet CIDR, and configure the network ACL to allow inbound TCP 3306 from the application security group ID.
Why it's wrong here
Security groups do not accept CIDR as a source when you need to restrict to a security group; using the subnet CIDR allows any instance in that subnet. Network ACLs cannot reference security group IDs at all. This combination is technically invalid for the NACL and does not achieve the precise restriction required.
- ✓
Configure the database security group to allow inbound TCP 3306 from the application security group ID, and leave the network ACL at its default allow-all state.
Why this is correct
Security groups are stateful and support referencing other security groups as sources, so allowing inbound TCP 3306 from the application security group ID ensures only instances with that security group can connect. The default NACL allows all traffic, so it does not interfere. This combination precisely meets the requirement without over-permitting.
- ✗
Configure the database security group to allow inbound TCP 3306 from the application security group ID, and configure the subnet's network ACL to allow inbound TCP 3306 from the application subnet CIDR only.
Why it's wrong here
Referencing the application security group ID in the database security group is correct, but network ACLs are stateless and operate at the subnet level; they cannot reference security group IDs. Using the application subnet CIDR in the NACL allows any instance in that subnet, not just the application security group, and may also block return traffic if outbound ephemeral ports are not allowed. This does not meet the requirement.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.