ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
You are defining the network topology for a three-tier web application to be deployed in a public cloud VPC. The design must allow users on the Internet to reach the web front-end, restrict access to the application tier, and keep the database tier completely inaccessible from external networks. Which component placement BEST satisfies these security requirements?
Place an Internet-facing load balancer in a public (DMZ) subnet; deploy web servers in a private subnet reachable only through the load balancer; put application servers in a second private subnet accessible only from the web tier; and isolate database servers in a third private subnet that accepts traffic solely from the application tier.
Host web and application servers together in a public subnet behind security groups, and locate the database in the same subnet secured with TLS.
Deploy web servers in a public subnet, with application and database servers in a shared private subnet protected only by host-based firewalls.
Put all three tiers in one private subnet and use network ACLs to block direct Internet access to the database.
A secure three-tier cloud architecture normally uses a public-facing load balancer (or similar reverse proxy) in a DMZ subnet to accept Internet traffic. The actual web servers reside in a private subnet and can be reached only through the load balancer. The application tier is placed in a second private subnet that accepts traffic only from the web tier, and the database tier is isolated in its own private subnet with inbound access permitted solely from the application servers. This structure enforces least privilege and defense-in-depth while still exposing the service to the public. The other options either collapse tiers into one subnet, expose internal tiers directly to the Internet, or rely only on host firewalls, all of which violate recommended segmentation practices.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Virtual Private Cloud (VPC) in cloud architecture?
Open an interactive chat with Bash
What is a DMZ subnet, and why is it important in network design?
Open an interactive chat with Bash
Why is network segmentation important in a three-tier architecture?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .