CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud security architect is designing the network segmentation for a three-tier web application hosted in a single Amazon VPC. The database tier must accept connections only from the application tier, and the application tier must accept connections only from the web tier. The architect wants the enforcement to be stateful, evaluated per elastic network interface, and independent of subnet CIDR ranges so that instances can be replaced without rewriting rules. Which control should the architect use to enforce this segmentation?
⚠ Common exam trap
The trap here is assuming that network ACLs provide the same stateful, group-referenced filtering as security groups, when ACLs are stateless and CIDR-based.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security groups attached to each tier's instances, referencing other security groups as sources
Security groups provide stateful, interface-level filtering and allow other security groups to be referenced as sources, which decouples the rules from subnet addressing. That combination satisfies the stateful, per-interface, CIDR-independent requirement and survives instance replacement. Subnet-level ACLs, route tables, and PrivateLink endpoints do not deliver group-based, stateful enforcement within a single VPC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A VPC peering connection between the three tier subnets with route table entries restricting traffic
Why it's wrong here
VPC peering connects separate VPCs and does not segment subnets within a single VPC. Route tables control where traffic is directed, not whether a connection is permitted, so they cannot enforce a default-deny posture between tiers. This control also does not evaluate per elastic network interface, making it unsuitable for the described tier isolation requirement.
- ✗
AWS PrivateLink endpoints published by each tier and consumed by the tier above it
Why it's wrong here
PrivateLink exposes a service through an interface endpoint backed by a Network Load Balancer, which is designed for service consumption across VPCs or accounts rather than intra-VPC tier segmentation. Introducing endpoints and load balancers for each tier adds cost and complexity without providing the per-interface, group-referenced stateful filtering the architect needs. It is a valid pattern for SaaS-style exposure, not for this internal segmentation.
- ✓
Security groups attached to each tier's instances, referencing other security groups as sources
Why this is correct
Security groups are stateful, attach to elastic network interfaces, and support referencing another security group as a source. This lets the database tier accept traffic only from the application tier's group, and the application tier only from the web tier's group, without hardcoding subnet CIDR ranges. Replacement instances that join the same group inherit the rules automatically, which matches the architect's requirements exactly.
- ✗
Network ACLs on each subnet, with rules that allow only the CIDR range of the adjacent tier's subnet
Why it's wrong here
Network ACLs are stateless and operate at the subnet boundary, so return traffic must be explicitly permitted by ephemeral port ranges. They also match on CIDR blocks, not on logical group membership, so any instance placed in the adjacent subnet would be allowed. When instances are replaced or subnets are re-addressed, the rules must be rewritten, which contradicts the stated design goal.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.