ISC2 Certified Cloud Security Professional (CCSP) Practice Question

In an Azure virtual network, a security team must ensure that production application VMs in the web subnet accept HTTP and HTTPS traffic from the Internet, block all other inbound connections, and allow SSH only from the corporate office's public IP address. The control must provide stateful packet filtering at layer 3/4, be applied directly to the subnet, and introduce no additional per-hour service cost. Which Azure network security control should be implemented?

  • Attach an Azure Network Security Group to the web subnet and create rules permitting TCP 80/443 from any source and TCP 22 only from the corporate office IP.

  • Provision Azure Bastion and configure its access policies to allow only HTTP, HTTPS, and SSH from approved sources.

  • Implement an Azure Application Gateway with a Web Application Firewall (WAF) and limit source IPs in the listener configuration.

  • Deploy Azure Firewall in the virtual network and define network and application rules to control HTTP, HTTPS, and SSH access.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot