CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud security engineer is designing network isolation for a multi-tier application in a single VPC. The database tier must accept connections only from the application tier, and the application tier must accept traffic only from the web tier. Which mechanism should the engineer use to enforce this at the instance level?
⚠ Common exam trap
The trap here is assuming subnet-level network ACLs can express tier-to-tier trust, when only security groups can reference other security groups as sources for instance-level enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security groups that reference other security groups as allowed sources
Security groups are stateful and evaluated at the instance's elastic network interface, and they uniquely support referencing another security group as an allowed source. That lets the engineer define the database tier as reachable only from members of the application tier's group, and the application tier as reachable only from the web tier's group. This logical, identity-based rule set preserves isolation as instances scale and change IP addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network ACLs applied to the subnets hosting each tier
Why it's wrong here
Network ACLs operate at the subnet boundary and are stateless, requiring explicit rules for both directions of traffic. They can filter by CIDR but cannot reference other security groups as sources, so they cannot express a rule such as allow traffic only from instances in the application tier's group. Using them alone forces brittle IP-based rules that break as instances scale or change addresses.
- ✗
VPC flow logs analyzed by a security information and event management system
Why it's wrong here
Flow logs capture metadata about accepted and rejected traffic for auditing and anomaly detection, but they are a detective control, not a preventive one. They record what happened after the fact and cannot block unauthorized connections between tiers. Relying on them for isolation would leave the database reachable by any source that lacks a blocking control in front of it.
- ✓
Security groups that reference other security groups as allowed sources
Why this is correct
Security groups are stateful, instance-level virtual firewalls that support referencing another security group as the source in an inbound rule. The database tier's group can allow traffic only from the application tier's group, and the application tier's group can allow traffic only from the web tier's group. This expresses tier isolation in terms of logical group membership rather than IP addresses, so it remains correct as instances scale.
- ✗
A route table that directs inter-tier traffic through a virtual appliance
Why it's wrong here
Route tables control where packets are sent, not whether they are permitted, so they cannot enforce the allow-only-from-specific-tier requirement by themselves. Inserting a virtual appliance adds inspection capability but also introduces a single point of failure and complexity without directly expressing the tier-to-tier trust relationship. The scenario asks for enforcement at the instance level, which routing does not provide.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.