ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A company is concerned that virtual machines in its public-cloud VPC can still initiate east-west connections to other subnets even when each subnet has its own network security group (NSG). The cloud security architect is told to move toward a zero-trust model so that every packet between workloads is evaluated against identity, device posture, and real-time context instead of static IP rules. Which control BEST meets this requirement without adding a traditional perimeter firewall appliance?
Migrate the workloads into a private cloud and separate them with dedicated VLANs.
Deploy a traditional next-generation firewall at the VPC's internet gateway to inspect all traffic.
Broaden the NSG CIDR ranges so all subnets are included under a single ruleset.
Implement microsegmentation with an identity-aware, software-defined firewall that applies tag-based policies at each workload.
Zero-trust networking assumes no implicit trust based on location inside the VPC. Microsegmentation tools embed a software-defined firewall on or very close to every workload and build policies tied to verified identity, tags, and context (such as device health or time of day). Because rules follow the workload and are evaluated for every east-west flow, this approach enforces the zero-trust principle of continuous, identity-centric verification. Perimeter firewalls and VLAN moves rely on coarse network boundaries, while widening CIDR blocks further weakens isolation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is microsegmentation in cloud security?
Open an interactive chat with Bash
What is the meaning of 'east-west traffic' in a network?
Open an interactive chat with Bash
How does zero-trust differ from traditional perimeter security approaches?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .