ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an architectural review of a new analytics cluster, you are asked to guarantee that system administrators can reach the nodes even if the production network is under active attack or mis-configured. Which design decision BEST meets this secure interface requirement?
Permit SSH to the existing production interface but restrict access to the data-center IP range with firewall rules.
Enable serial console logging on all servers so that administrators can view output if the network fails.
Provide each node with a separate network interface cabled to a physically isolated management VLAN that is reachable solely through a VPN requiring multi-factor authentication.
Expose an HTTPS-based management REST API on the public load balancer and protect it with a long, random API key.
Out-of-Band (OOB) management requires an interface that is completely isolated from normal production data paths so that administrative access is still possible when the business network is congested, attacked, or otherwise unavailable. A dedicated management network reached only through a strongly authenticated VPN enforces this physical and logical separation and limits exposure. Relying on the production interface with IP filtering or HTTPS leaves management traffic on the same potentially compromised network. Publishing management APIs through a load balancer, even with API keys, likewise offers no true separation. Printing console output to the serial port helps with troubleshooting but does not allow remote, authenticated management or guarantee availability when the network is down. Therefore, the dedicated, isolated management network with MFA-protected VPN is the only option that fully satisfies secure OOB management requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Out-of-Band (OOB) management?
Open an interactive chat with Bash
What is a management VLAN and why is it physically isolated?
Open an interactive chat with Bash
Why is a VPN with multi-factor authentication (MFA) required for secure access?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .