CCSP Cloud Platform and Infrastructure Security Practice Question
A startup runs a three-tier web application on cloud virtual machines. The database tier must accept connections only from the application tier and never from the internet. Which cloud network security control should the team implement to enforce this requirement with the least operational overhead?
⚠ Common exam trap
The trap here is choosing a subnet-level deny or a public IP allow, which either blocks legitimate traffic or requires constant manual updates as the application tier scales.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A security group on the database instances allowing only the application tier's security group as source
Referencing the application tier's security group as the source of the database rule creates a dynamic, identity-based allow that follows instances as they scale. Because membership is managed automatically, the team avoids editing CIDR ranges or host firewalls whenever the application tier changes, meeting the segmentation goal with the least ongoing effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A network ACL on the database subnet denying all inbound traffic
Why it's wrong here
A blanket deny on the database subnet would block the application tier as well as the internet, breaking the three-tier application. Network ACLs are stateless and subnet-scoped, so crafting exceptions still requires maintaining explicit CIDR ranges for every application instance, which is more operational overhead than the requirement calls for.
- ✗
A host-based firewall rule on each database VM allowing the application tier's public IP address
Why it's wrong here
Referencing a public IP address ties the rule to a specific address that changes whenever the application tier scales or is replaced. Each change requires editing host firewall configuration on every database VM, producing exactly the operational burden the team wants to avoid, and it exposes the database to any host that later acquires that address.
- ✓
A security group on the database instances allowing only the application tier's security group as source
Why this is correct
Security groups can reference another security group as a source, so the database rule permits traffic only from instances that carry the application tier's group membership. As the application tier scales in or out, membership updates automatically, requiring no rule edits, which satisfies the requirement with minimal ongoing operational effort.
- ✗
A web application firewall inspecting SQL traffic bound for the database
Why it's wrong here
A web application firewall inspects HTTP and HTTPS application-layer requests, not raw database protocol connections, and it does not restrict which hosts may open a socket. It could help detect injection attempts but would not enforce the network segmentation requirement, and it adds a component to manage rather than reducing overhead.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.