ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization has deployed a three-tier web application in a public cloud. Web servers sit in a public subnet behind a load balancer, while application and database servers reside in a private subnet that currently has no inbound rules. Administrators must occasionally use SSH from the corporate network to manage the private servers, but security policy forbids exposing SSH from the Internet. Which network security control best satisfies the requirement while minimizing the private subnet's attack surface?
Deploy a hardened bastion (jump) host in a small public or dedicated management subnet and require administrators to SSH to private servers through it
Install host-based intrusion detection systems on all private instances to block unauthorized SSH attempts
Place a honeypot in the private subnet to attract and contain external attackers
Add an inbound security group rule permitting SSH from any source to the private subnet during approved maintenance windows
A bastion host (sometimes called a jumpbox or jump host) is a hardened system placed in a minimally sized, locked-down public or management subnet. Administrators connect to the bastion first-typically over SSH or RDP restricted to known corporate IPs-and from there pivot to resources in private subnets. This centralizes and audits management access while keeping direct inbound connectivity to the private instances closed.
Choosing a broader network security group rule that allows SSH from anywhere violates the security requirement. A host-based IDS can detect attacks but does not provide controlled administrative access, and a honeypot diverts attackers rather than enabling secure management connectivity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a bastion host and why is it used?
Open an interactive chat with Bash
How does a bastion host differ from a honeypot?
Open an interactive chat with Bash
Why is allowing SSH from any source to the private subnet a security risk?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .