ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A company migrates its on-premises HR portal to AWS. The portal runs on EC2 instances in two private subnets of a VPC and must be reachable only from the corporate offices over an existing Direct Connect and Site-to-Site VPN. No internet-based access is allowed. Which design best enforces an intranet security zone for this workload while remaining highly available?
Publish the application through Amazon CloudFront and API Gateway with IAM authentication, allowing access only to authenticated employees.
Use a Network Load Balancer fronted by AWS Global Accelerator; allow traffic only from the accelerator's static IP addresses.
Create an internal Application Load Balancer in the two private subnets, attach the VPC to an AWS Transit Gateway that advertises the private prefixes to Direct Connect and VPN, and do not attach an internet gateway to the VPC.
Deploy a public Application Load Balancer in public subnets and restrict its security group to corporate office CIDR blocks.
An internal Application Load Balancer placed in private subnets exposes only private IP addresses, so it can be reached through Direct Connect or the VPN but is never published to the internet. Routing the on-premises networks through a transit gateway keeps connectivity scalable while the absence of an internet gateway prevents accidental public exposure. The other options either rely on public-facing services (public ALB, Global Accelerator, CloudFront, API Gateway) or still require an internet gateway, which contradicts the requirement for an intranet-only zone.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an AWS Transit Gateway?
Open an interactive chat with Bash
What is the difference between a private and public Application Load Balancer?
Open an interactive chat with Bash
Why is an internet gateway excluded for enforcing an intranet security zone?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .