ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A company hosts a three-tier application (web, API, and database servers) on an IaaS public cloud. All virtual machines currently reside in one flat virtual network, and an edge firewall only filters north-south traffic. A recent audit requires the environment to follow a zero trust network model so that every east-west flow is explicitly authorized. Which redesign using the cloud provider's native controls BEST satisfies this requirement?

  • Consolidate all servers into a larger subnet and enable source NAT on the Internet gateway to hide internal addresses.

  • Place each tier in its own subnet and attach network security groups that whitelist only the required ports between specific workloads, with a default deny rule for all other intra-VNet traffic.

  • Add an intrusion detection sensor to the Internet-facing load balancer while leaving the existing flat network and security rules unchanged.

  • Deploy a next-generation firewall appliance at the virtual network edge and permit any traffic once packets pass through the appliance.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot