ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your company is moving a three-tier customer portal to a public IaaS provider. Web servers in a public subnet will query the application servers in a private subnet, which in turn connect to a managed database service. Compliance policy states that any sensitive data traversing the provider's internal network must be protected against disclosure even if another tenant gains packet-sniffing capability. The application team cannot modify existing code and wants to avoid significant re-architecture. Which security control BEST meets the requirement?
Configure host-based IPsec VPN tunnels between the web and application server instances.
Place the web and application tiers in the same VLAN to eliminate intermediate hops.
Apply stateful security group rules to allow only TCP port 443 from web to application servers.
Enable client-side encryption for all database queries using the provider's SDK.
Using host-based IPsec tunnels encrypts every packet exchanged between the web and application servers at the network layer, providing confidentiality even if the cloud provider's internal network is monitored. Because IPsec operates transparently to applications, it requires no changes to existing code or the overall application design. Security groups or firewalls restrict traffic but do not protect data from interception. Client-side database encryption secures only the database connection and would still leave web-to-application traffic unprotected, besides requiring code changes to invoke the SDK. Placing both tiers in the same VLAN may reduce hops but offers no encryption, so data could still be captured in clear text. Therefore, host-based IPsec is the most appropriate control for protecting intra-tier communications with minimal disruption.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is IPsec VPN and how does it work?
Open an interactive chat with Bash
Why is a host-based IPsec VPN better than security group rules in this scenario?
Open an interactive chat with Bash
How does IPsec operate transparently without changing application code?
Open an interactive chat with Bash
What is IPsec and how does it work?
Open an interactive chat with Bash
Why are stateful security group rules insufficient for protecting sensitive data from packet sniffing?
Open an interactive chat with Bash
What are the advantages of host-based IPsec tunnels compared to VLAN-based network segmentation?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .