🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A company migrates its on-premises HR portal to AWS. The portal runs on EC2 instances in two private subnets of a VPC and must be reachable only from the corporate offices over an existing Direct Connect and Site-to-Site VPN. No internet-based access is allowed. Which design best enforces an intranet security zone for this workload while remaining highly available?

  • Publish the application through Amazon CloudFront and API Gateway with IAM authentication, allowing access only to authenticated employees.

  • Use a Network Load Balancer fronted by AWS Global Accelerator; allow traffic only from the accelerator's static IP addresses.

  • Create an internal Application Load Balancer in the two private subnets, attach the VPC to an AWS Transit Gateway that advertises the private prefixes to Direct Connect and VPN, and do not attach an internet gateway to the VPC.

  • Deploy a public Application Load Balancer in public subnets and restrict its security group to corporate office CIDR blocks.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot