ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your company is moving a three-tier customer portal to a public IaaS provider. Web servers in a public subnet will query the application servers in a private subnet, which in turn connect to a managed database service. Compliance policy states that any sensitive data traversing the provider's internal network must be protected against disclosure even if another tenant gains packet-sniffing capability. The application team cannot modify existing code and wants to avoid significant re-architecture. Which security control BEST meets the requirement?

  • Configure host-based IPsec VPN tunnels between the web and application server instances.

  • Place the web and application tiers in the same VLAN to eliminate intermediate hops.

  • Apply stateful security group rules to allow only TCP port 443 from web to application servers.

  • Enable client-side encryption for all database queries using the provider's SDK.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot