ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A cloud service provider is designing a new multitenant IaaS data center. Each rack contains hypervisors that will host virtual machines from many different customers on the same top-of-rack switches. To keep the hypervisor service consoles reachable only by the provider's operations team and to eliminate any possibility of tenant traffic reaching the management plane, which design choice best satisfies this requirement?

  • Deploy a physically separate out-of-band management network, using dedicated switch ports, private VLANs or VRFs, and firewalls that allow access only from the operations subnet.

  • Create a single shared management VLAN that both providers and tenants can join, securing it with port-security limits on the switch.

  • Place the management interfaces in the same VLAN as tenant storage traffic but protect each hypervisor with a host-based firewall.

  • Rely on role-based access control in the hypervisor management application and allow the interfaces to remain reachable from every tenant network.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot