ISC2 Certified Cloud Security Professional (CCSP) Practice Question

During deployment of a new cloud management appliance that will orchestrate virtual machines across multiple hypervisor clusters, the cloud operations team wants to minimize the risk that tenant traffic could be used to reach the appliance. Which network design change should be implemented before placing the appliance into production?

  • Enable switch port mirroring and send a copy of tenant traffic to the appliance for inspection.

  • Assign the appliance a routable IP on the same VLAN as tenant VMs and rely on its host-based firewall for access control.

  • Connect the appliance directly to the storage network so that it bypasses the compute fabric.

  • Place the appliance interface in a dedicated out-of-band VLAN reachable only through a jump host that enforces SSH and MFA.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot