CompTIA Cloud+ (CV0-004)TroubleshootingHard

A compliance auditor reports that a critical database containing sensitive customer data is accessible from the public internet, despite the cloud administrator having configured a security group to only allow traffic from the application's private subnet. Further investigation reveals that the database instance also has a public IP address assigned. What is the MOST likely cause of this security vulnerability?

  1. AThe database instance is in a public subnet, overriding the security group's private ingress rules.
  2. BThe security group is stateful, allowing return traffic even if outbound rules are restrictive.
  3. CAn Internet Gateway is attached to the VPC, implicitly allowing all outbound traffic.
  4. DA Network Access Control List (NACL) associated with the database's subnet is permitting public inbound traffic.
Show answer & explanation

Correct answer: D. A Network Access Control List (NACL) associated with the database's subnet is permitting public inbound traffic.

Security groups are instance-level firewalls. However, NACLs operate at the subnet level and are stateless. If a NACL permits public inbound traffic to a subnet, it will override the more granular security group rules at the instance level for traffic that is explicitly allowed by the NACL.

Why the other options are wrong

  • A. While being in a public subnet is necessary for public IP access, the security group should still control inbound traffic. The question implies the security group is correctly configured, pointing to a conflicting or overriding control like a NACL.
  • B. Statefulness of security groups relates to return traffic, not initial inbound access from the public internet.
  • C. An Internet Gateway allows outbound traffic to the internet but doesn't implicitly allow inbound public traffic to instances unless specifically routed and permitted by other controls.

NACL vs. Security Group

Network Access Control Lists (NACLs) are stateless subnet-level firewalls, while Security Groups are stateful instance-level firewalls.

  • NACLs process rules in order; Security Groups process all rules.
  • NACLs can deny traffic; Security Groups only allow traffic.
  • Both are critical for granular network security in cloud environments.

Memory trick: Layered Security, Check Every Gate.

More Troubleshooting questions