hardMultiple ChoiceObjective-mapped
CCSP Practice Question: A multi-tier web application is deployed across…
A multi-tier web application is deployed across two VPCs connected via VPC peering. The web tier in VPC A must communicate with the database tier in VPC B on port 3306. Security groups are used for instance-level security. Which security group configuration is MOST secure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the database security group, add an inbound rule allowing TCP/3306 from the security group ID of the web servers.
The most secure approach is to allow inbound traffic to the database security group from the web server security group by referencing its ID (security group ID). This ensures that only instances in the web server security group can reach the database, regardless of IP changes. Option A is correct because it uses a security group ID reference, which is more specific and secure than using a CIDR range. Options B, C, and D are less secure: B involves a VPN and routing, which are not instance-level; C uses a network ACL which is stateless and less granular; D uses a CIDR range which allows any instance in VPC A to connect, not just the web servers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
In the database security group, add an inbound rule allowing TCP/3306 from the security group ID of the web servers.
Why this is correct
Security group referencing ensures only instances in the web security group can connect.
- ✗
Configure a VPN connection between VPCs and use route tables to direct traffic.
Why it's wrong here
VPN adds complexity but does not replace the need for security group rules.
- ✗
In the network ACL for VPC B's subnet, add an inbound rule allowing TCP/3306 from VPC A CIDR.
Why it's wrong here
NACLs are stateless and subnet-level; not instance-level control.
- ✗
In the database security group, add an inbound rule allowing TCP/3306 from the VPC A CIDR.
Why it's wrong here
IP-based rules are less granular and do not adapt to dynamic IPs.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.