Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A startup runs a three-tier web application on cloud virtual machines. The database tier must accept connections only from the application tier and never from the internet. Which cloud network security control should the team implement to enforce this requirement with the least operational overhead?

⚠ Common exam trap

The trap here is choosing a subnet-level deny or a public IP allow, which either blocks legitimate traffic or requires constant manual updates as the application tier scales.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A security group on the database instances allowing only the application tier's security group as source

Referencing the application tier's security group as the source of the database rule creates a dynamic, identity-based allow that follows instances as they scale. Because membership is managed automatically, the team avoids editing CIDR ranges or host firewalls whenever the application tier changes, meeting the segmentation goal with the least ongoing effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A network ACL on the database subnet denying all inbound traffic

    Why it's wrong here

    A blanket deny on the database subnet would block the application tier as well as the internet, breaking the three-tier application. Network ACLs are stateless and subnet-scoped, so crafting exceptions still requires maintaining explicit CIDR ranges for every application instance, which is more operational overhead than the requirement calls for.

  • ✗

    A host-based firewall rule on each database VM allowing the application tier's public IP address

    Why it's wrong here

    Referencing a public IP address ties the rule to a specific address that changes whenever the application tier scales or is replaced. Each change requires editing host firewall configuration on every database VM, producing exactly the operational burden the team wants to avoid, and it exposes the database to any host that later acquires that address.

  • ✓

    A security group on the database instances allowing only the application tier's security group as source

    Why this is correct

    Security groups can reference another security group as a source, so the database rule permits traffic only from instances that carry the application tier's group membership. As the application tier scales in or out, membership updates automatically, requiring no rule edits, which satisfies the requirement with minimal ongoing operational effort.

  • ✗

    A web application firewall inspecting SQL traffic bound for the database

    Why it's wrong here

    A web application firewall inspects HTTP and HTTPS application-layer requests, not raw database protocol connections, and it does not restrict which hosts may open a socket. It could help detect injection attempts but would not enforce the network segmentation requirement, and it adds a component to manage rather than reducing overhead.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.