CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud security engineer is configuring network security for a multi-tier application in AWS. The web servers must be accessible from the internet on port 443, the application servers should only receive traffic from the web servers, and the database servers should only accept traffic from the application servers on port 3306. Which combination of security controls should be used?
⚠ Common exam trap
CCSP often tests the difference between security groups (stateful, instance-level, allow rules only) and NACLs (stateless, subnet-level, allow/deny rules), and candidates may incorrectly choose NACLs for dynamic, least-privilege control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security groups with source referencing the web server security group for app tier, and app server security group for DB tier
In AWS, security groups are stateful virtual firewalls that can reference other security groups as sources. For the web tier, allow inbound 443 from 0.0.0.0/0. For the app tier, allow inbound from the web server security group. For the DB tier, allow inbound on 3306 from the app server security group. This creates a least-privilege, layered defense without hardcoding IP addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security groups with source referencing the web server security group for app tier, and app server security group for DB tier
Why this is correct
Security groups support source referencing, so the app tier's inbound rule names the web server security group and the database tier's names the app server security group. This enforces the tiered traffic flow on port 3306 without hard-coded CIDRs, satisfying the stem's constraints.
- ✗
NACLs on each subnet with rules referencing source IP ranges
Why it's wrong here
NACLs are stateless and evaluate subnet CIDR ranges, so referencing source IP ranges cannot express the security-group membership of web or application instances as they scale. NACLs are tempting for subnet-level segmentation, and would be correct for coarse stateless allow/deny rules at subnet boundaries.
- ✗
A single NACL applied to all subnets with layer 7 filtering
Why it's wrong here
A single NACL across all subnets cannot enforce per-tier isolation, and NACLs operate at layers 3 and 4, not layer 7. NACLs are tempting because they are the subnet-level control, and a shared NACL would be correct for uniform, stateless filtering applied identically to every subnet.
- ✗
Route tables with deny rules to restrict inter-subnet traffic
Why it's wrong here
Route tables direct traffic by destination prefix and contain no deny rules, so they cannot restrict which instances reach a tier. They are tempting because they govern inter-subnet reachability, and route tables would be correct for steering traffic through a transit gateway or NAT rather than for security policy.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.