🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A company is migrating its internal payroll application to AWS. Compliance requires that EC2 application servers are never reachable from the public internet, yet they must download OS and antivirus updates from the internet. Users in the on-premises data center must initiate SSH sessions to the servers over an encrypted link. The design must be highly available and demand minimal operational management. Which solution best meets these requirements?

  • Place the application servers in a private subnet; attach an Internet Gateway; add outbound-only rules in the servers' security group; configure a Site-to-Site VPN for corporate access; do not deploy any NAT device.

  • Place the application servers in a private subnet that also hosts a single t3.micro NAT instance; create an AWS Client VPN endpoint for corporate users; route all internet and VPN traffic through the NAT instance.

  • Place the application servers in a public subnet with Elastic IP addresses; restrict inbound traffic to SSH only; provide corporate access through an AWS Client VPN endpoint; no NAT device is needed.

  • Place the application servers in a private subnet; create two public subnets each hosting an AWS NAT Gateway; add a default route from the private subnet to the NAT Gateways; attach a Virtual Private Gateway and establish a Site-to-Site VPN from the data center; no inbound rules from the internet are required.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot