ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A cloud provider is designing a new private IaaS data center that will host multiple customers who may use the same RFC 1918 address space. Security policy states that if a hypervisor or virtual switch is compromised, an attacker must still be unable to sniff or inject traffic into another tenant's network. Which network segmentation approach best satisfies these requirements during the logical design phase?

  • Create a dedicated VRF for each tenant and transport it across the fabric with a VXLAN overlay.

  • Assign a unique IEEE 802.1Q VLAN to each tenant and trunk those VLANs throughout the data center.

  • Rely on hypervisor security groups to filter inter-tenant traffic on every virtual switch port.

  • Use a single shared network while enforcing strict role-based access control in the cloud management plane.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot