Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud security engineer is configuring network security for a multi-tier application in AWS. The web servers must be accessible from the internet on port 443, the application servers should only receive traffic from the web servers, and the database servers should only accept traffic from the application servers on port 3306. Which combination of security controls should be used?

⚠ Common exam trap

CCSP often tests the difference between security groups (stateful, instance-level, allow rules only) and NACLs (stateless, subnet-level, allow/deny rules), and candidates may incorrectly choose NACLs for dynamic, least-privilege control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security groups with source referencing the web server security group for app tier, and app server security group for DB tier

In AWS, security groups are stateful virtual firewalls that can reference other security groups as sources. For the web tier, allow inbound 443 from 0.0.0.0/0. For the app tier, allow inbound from the web server security group. For the DB tier, allow inbound on 3306 from the app server security group. This creates a least-privilege, layered defense without hardcoding IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security groups with source referencing the web server security group for app tier, and app server security group for DB tier

    Why this is correct

    Security groups support source referencing, so the app tier's inbound rule names the web server security group and the database tier's names the app server security group. This enforces the tiered traffic flow on port 3306 without hard-coded CIDRs, satisfying the stem's constraints.

  • ✗

    NACLs on each subnet with rules referencing source IP ranges

    Why it's wrong here

    NACLs are stateless and evaluate subnet CIDR ranges, so referencing source IP ranges cannot express the security-group membership of web or application instances as they scale. NACLs are tempting for subnet-level segmentation, and would be correct for coarse stateless allow/deny rules at subnet boundaries.

  • ✗

    A single NACL applied to all subnets with layer 7 filtering

    Why it's wrong here

    A single NACL across all subnets cannot enforce per-tier isolation, and NACLs operate at layers 3 and 4, not layer 7. NACLs are tempting because they are the subnet-level control, and a shared NACL would be correct for uniform, stateless filtering applied identically to every subnet.

  • ✗

    Route tables with deny rules to restrict inter-subnet traffic

    Why it's wrong here

    Route tables direct traffic by destination prefix and contain no deny rules, so they cannot restrict which instances reach a tier. They are tempting because they govern inter-subnet reachability, and route tables would be correct for steering traffic through a transit gateway or NAT rather than for security policy.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.