ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During the logical design of an on-premises private cloud, you must ensure that virtual machines owned by different internal tenants remain isolated even when they vMotion between hosts in the same cluster. Security staff want to enforce firewall rules that follow each workload and are expressed in terms of VM tags rather than IP subnets. They also need to avoid frequent reconfiguration of upstream switches. Which design choice BEST satisfies these requirements?
Creating separate virtual routing and forwarding (VRF) instances for every tenant at the data-center core
Installing additional physical NICs in each host and mapping one to each tenant network
Assigning a dedicated VLAN and subnet to each tenant on the physical switches
Hypervisor-based microsegmentation using distributed virtual switches and security groups
Hypervisor-based microsegmentation implemented with distributed virtual switches or a virtual overlay such as VXLAN/GENEVE provides per-VM stateful firewalling that is tied to VM metadata. Policies follow the workload automatically during vMotion because enforcement occurs inside each hypervisor rather than on physical switches. VLANs or VRF instances offer layer-2/3 segmentation but depend on static network constructs and require changes to physical infrastructure when applications move or new subnets are added. Dedicating physical NICs to each tenant cannot scale in a multi-tenant cloud and still leaves east-west traffic uninspected.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is hypervisor-based microsegmentation?
Open an interactive chat with Bash
How is microsegmentation different from using VLANs or VRF for segmentation?
Open an interactive chat with Bash
What is vMotion and how does it impact security design?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .