ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A DevOps team has deployed a three-tier application to a public IaaS provider. All virtual machines (web, application, and database) reside in the same virtual network and currently share one permissive security group that allows any TCP/UDP traffic between members. During an internal audit, the CISO requests that the environment be aligned with zero-trust networking principles to curb lateral movement while avoiding additional hardware appliances or major architectural changes.

Which action will BEST meet the CISO's requirement?

  • Move all instances to a private subnet and rely on the provider's default network ACLs to block unwanted traffic.

  • Enable host-based firewalls inside every VM but leave the existing permissive security group unchanged.

  • Deploy a virtual next-generation firewall in a separate transit VPC and mirror all virtual network traffic to it for inspection.

  • Create distinct, least-privilege security groups for each tier and only allow the minimum required ports between specific groups while denying all other traffic.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot