🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A company is migrating its web tier to a private cloud that uses a distributed virtual switch on each host. Policy requires that every inbound HTTP/HTTPS session be inspected and, if needed, blocked before reaching any web server. The network team also wants to avoid changing server IPs or routing tables. Which deployment option best meets these constraints for the new virtual web application firewall (vWAF)?

  • Attach the vWAF to a SPAN/mirror port on the distributed virtual switch to monitor traffic passively.

  • Install the vWAF software on the hypervisor management network so it can inspect traffic out of band for all virtual machines.

  • Deploy a vWAF agent inside each web server virtual machine to perform host-based inspection after packets are delivered.

  • Deploy the vWAF as a two-interface, layer-2 bridge VM connected between the external and web-tier port groups on the distributed virtual switch, operating inline.

ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot