ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A fintech startup is refactoring its monolithic payment system into several microservices that will run on the cloud provider's managed Kubernetes platform. Compliance mandates state that all pod-to-pod (east-west) traffic must be encrypted in transit and that each microservice must be able to prove its identity so it can decrypt only the data it is explicitly authorized to access. Which cloud-native architectural feature will best meet both security requirements with minimal application code changes?

  • Place a cloud web application firewall in front of every microservice ingress endpoint to inspect and filter traffic.

  • Implement a service mesh that injects sidecar proxies and enforces mutual TLS with certificates issued by the provider's private CA.

  • Enable server-side encryption with customer-managed keys on the object storage used for configuration files.

  • Create a dedicated network security group for each pod and restrict ingress and egress ports to required services only.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot