🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A company is migrating a three-tier web application to AWS. The security team mandates four separate network security zones: an Internet zone, a DMZ for public web endpoints, an intranet zone for application and database tiers, and an extranet that lets business partners reach specific APIs without exposing them publicly. Which AWS design best enforces these zones while limiting unnecessary exposure?

  • Expose web, application, and database tiers through AWS Global Accelerator; segregate partner traffic with IAM roles but keep all instances in private subnets.

  • Create a public subnet with an Internet Gateway for an internet-facing Application Load Balancer (DMZ); place web, application, and database instances in private subnets without an Internet Gateway; add a dedicated extranet subnet that terminates a Site-to-Site VPN and routes only to the application tier.

  • Deploy all three tiers in one public subnet behind a Web Application Firewall and control access exclusively with security groups; allow partners to connect over the same public endpoint.

  • Host web and application servers together in a public subnet, the database in a private subnet, and provide partner access through the internet-facing load balancer using API keys.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot