CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is deploying a new web application into a multi-cloud environment. The application's database contains highly sensitive customer data, and the organization requires a solution that provides granular control over network access to the database, ensuring that only specific application instances from a particular Virtual Private Cloud (VPC) can connect to it, and that all other traffic is implicitly denied. Which network security construct should the architect use to achieve this precise level of access control?

  1. ANetwork Access Control Lists (NACLs).
  2. BVPC Peering.
  3. CSecurity Groups.
  4. DDirect Connect.
Show answer & explanation

Correct answer: C. Security Groups.

Security Groups operate at the instance level and provide stateful filtering, meaning they implicitly deny all inbound traffic unless explicitly allowed. This granular control allows the architect to specify exactly which application instances (or IP ranges) can access the database, ensuring all other traffic is denied, fulfilling the requirement for precise access control.

Why the other options are wrong

  • A. NACLs are stateless and operate at the subnet level. While they can deny traffic, they require both inbound and outbound rules for each port, and are less granular than security groups for instance-level control.
  • B. VPC Peering connects two VPCs, allowing them to communicate as if they were on the same network, but it does not provide granular instance-level access control to a database.
  • D. Direct Connect establishes a dedicated network connection from on-premises to a cloud provider, which is for connectivity, not for granular instance-level access control within a VPC.

Security Groups (Cloud)

In cloud environments (e.g., AWS, Azure), Security Groups act as virtual firewalls that control inbound and outbound traffic for one or more instances. They are stateful and implicitly deny all traffic unless explicitly allowed.

  • Operate at the instance level.
  • Stateful (return traffic is automatically allowed).
  • Implicitly deny all inbound traffic unless allowed.
  • Allow granular control based on IP addresses, other security groups, and ports.

Memory trick: Security Groups are like a bouncer for each database server, only letting in specific, pre-approved guests.

More Security Architecture questions