ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization has deployed a three-tier application (web, application, database) in separate subnets inside the same public-cloud virtual network. A new policy now requires that all traffic flowing between those subnets be encrypted while in transit, but the development team cannot modify or recompile the application code. Which infrastructure-level security control will best meet this requirement with the least impact on the workloads themselves?

  • Terminate TLS sessions on an internet-facing load balancer in front of the web tier.

  • Enable server-side encryption with customer-managed keys (CMKs) on the block storage volumes used by each tier.

  • Create IPsec VPN tunnel-mode connections between the subnets by configuring the cloud provider's virtual routers or gateways.

  • Apply restrictive stateful security group rules to permit only required TCP and UDP ports between the subnets.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot