ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A SaaS provider wants to reduce the risk that a compromise in one tenant's virtual machine will let an attacker move laterally to other tenants inside the same cloud data center. Budget allows changes in the virtualized network layer but no hardware refresh. Which control will most directly mitigate this risk?
Enable port security on each top-of-rack switch to restrict the number of MAC addresses per access port.
Configure DNSSEC for the provider's internal authoritative DNS zones to prevent spoofed responses.
Add erasure-coded storage across availability zones to increase data redundancy for every tenant.
Deploy microsegmentation policies enforced by a distributed firewall on the hypervisor's virtual switch.
Lateral movement between VMs in a multi-tenant environment is best stopped by enforcing fine-grained segmentation at the virtual switch or hypervisor layer. Microsegmentation uses distributed firewalls or similar controls to apply stateful rules to every VM's vNIC, so traffic is only permitted when explicitly authorized. Port security on physical switches limits MAC spoofing on a port but does not inspect or filter east-west traffic once it reaches the virtual switch. Increasing storage redundancy addresses data durability, not network movement, and DNSSEC protects name resolution integrity, not VM-to-VM traffic. Therefore, microsegmentation with a distributed firewall is the most effective mitigation in this scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is microsegmentation in cloud security?
Open an interactive chat with Bash
How does a distributed firewall work?
Open an interactive chat with Bash
Why is port security not effective for inter-VM lateral movement prevention?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .