ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your company runs a three-tier web service spread across two availability zones in a public IaaS cloud. A penetration test shows that SQL queries exchanged between the application servers and the back-end database virtual machines are sent in clear text over the provider's virtual network. Refactoring the application to use TLS would require significant code rewrites and cannot be completed in the short term. To comply quickly with a new policy that mandates encryption of all sensitive data in transit, which control should you implement first to protect this traffic while imposing the least change on the existing application design?

  • Deploy a cloud web application firewall (WAF) in front of the web tier to inspect and sanitize SQL traffic.

  • Enable full-disk encryption on the database virtual machine volumes with provider-managed keys.

  • Configure host-based IPsec in transport mode between the application and database virtual machines, using centrally managed security policies.

  • Move both tiers into a private subnet so their traffic never leaves the provider's data center network.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot