ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A company hosts a three-tier application (web, API, and database servers) on an IaaS public cloud. All virtual machines currently reside in one flat virtual network, and an edge firewall only filters north-south traffic. A recent audit requires the environment to follow a zero trust network model so that every east-west flow is explicitly authorized. Which redesign using the cloud provider's native controls BEST satisfies this requirement?
Deploy a next-generation firewall appliance at the virtual network edge and permit any traffic once packets pass through the appliance.
Add an intrusion detection sensor to the Internet-facing load balancer while leaving the existing flat network and security rules unchanged.
Place each tier in its own subnet and attach network security groups that whitelist only the required ports between specific workloads, with a default deny rule for all other intra-VNet traffic.
Consolidate all servers into a larger subnet and enable source NAT on the Internet gateway to hide internal addresses.
Zero trust removes implicit trust based on network location and requires that every connection be explicitly authenticated, authorized, and logged. Implementing micro-segmentation with the provider's network security groups (or equivalent) lets the architect create fine-grained, least-privilege rules between workloads-for example, allowing the web tier to reach the API tier on TCP 443 while denying all other traffic by default. Simply adding perimeter devices or enlarging subnets retains implicit trust inside the boundary and therefore does not meet zero trust objectives, nor does placing sensors that only monitor rather than enforce policy.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the zero trust network model?
Open an interactive chat with Bash
What are network security groups (NSGs) in a cloud environment?
Open an interactive chat with Bash
What is micro-segmentation in relation to zero trust?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .