🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your organization is migrating a two-tier web application to AWS. Corporate policy requires a demilitarized zone (DMZ) that exposes only the web tier to the Internet while preventing any direct inbound connectivity to the application and database tiers. Which Amazon VPC design best meets this requirement following AWS security best practices?

  • Deploy the web, application, and database instances together in a single public subnet protected solely by security groups that allow TCP 80 and 443 from 0.0.0.0/0.

  • Build two VPCs, one for the web tier and one for the internal tiers, peer them, and attach an Internet Gateway to both so each tier can receive client requests directly.

  • Place all tiers in a single private subnet and publish the web application to the Internet by assigning an Elastic IP address to a NAT gateway in that subnet.

  • Create separate public and private subnets within one VPC; attach an Internet Gateway to the public subnets for the web tier, place application and database instances in private subnets reachable only from the web tier, and use a NAT gateway for their outbound traffic.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot