CCSP Cloud Platform and Infrastructure Security Practice Question
A healthcare company is migrating a legacy three-tier application to AWS. The security team must ensure that the database tier is reachable only from the application tier, that the rule follows the application instances automatically as they scale, and that no rule permits a broader source. Which mechanism should the team use?
⚠ Common exam trap
The trap here is choosing a CIDR-based rule because it feels more precise, when only a security-group reference automatically follows elastic instances and excludes unrelated workloads in the same subnet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A security group on the database instances whose inbound rule references the security group ID of the application tier.
A security group rule that names the application tier's security group as its source gives an identity-based, stateful permission that tracks instances through scaling events and excludes every other resource in the VPC. CIDR-based subnet filters and VPC-wide rules are broader than needed, and PrivateLink does not address intra-VPC tier isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A network ACL on the database subnet that allows inbound traffic only from the application subnet CIDR range.
Why it's wrong here
Network ACLs are stateless subnet-level filters that reference CIDR blocks, so they cannot follow instances as they scale and they permit anything in the application subnet, including unrelated workloads. They also require separate rules for return traffic. This neither restricts the source to the application tier nor adapts to elastic scaling.
- ✗
A security group on the database instances that allows inbound traffic from the VPC CIDR range on the database port.
Why it's wrong here
Allowing the entire VPC CIDR means every resource in the VPC, including developer workstations and unrelated services, can reach the database. It satisfies reachability but violates the requirement that no rule permit a broader source. It also does not distinguish the application tier from any other workload sharing the VPC address space.
- ✗
AWS PrivateLink endpoint policies that restrict which application-tier principals may open connections to the database.
Why it's wrong here
PrivateLink is designed for exposing services across VPCs and accounts through interface endpoints, not for gating access between tiers inside a single VPC. Endpoint policies govern which principals may use the endpoint, not which instances may reach a database, so this adds complexity without enforcing the tier-to-tier rule the scenario requires.
- ✓
A security group on the database instances whose inbound rule references the security group ID of the application tier.
Why this is correct
Referencing the application tier's security group as the source means any instance that carries that group is automatically allowed, so newly launched application instances are covered without rule changes. No CIDR is involved, so nothing in the VPC outside the application tier can connect, and the rule is stateful, so return traffic needs no extra configuration.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.