🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security administrator is deploying a Linux-based web application on an Amazon EC2 instance inside a new VPC. The instance must accept HTTPS traffic from any Internet host, permit SSH administration only from the company's head-office CIDR block 203.0.113.0/24, and allow the instance to download operating-system patches from Internet-based repositories over TCP port 443 while blocking all other outbound ports. Which security group configuration best satisfies these requirements while adhering to the principle of least privilege?

  • Inbound: TCP 443 from 0.0.0.0/0 and TCP 22 from 203.0.113.0/24; Outbound: TCP ports 1024-65535 to 0.0.0.0/0

  • Inbound: TCP 443 from 0.0.0.0/0 only; Outbound: no rules (default deny)

  • Inbound: TCP 443 from 0.0.0.0/0 and TCP 22 from 0.0.0.0/0; Outbound: TCP 443 to 0.0.0.0/0

  • Inbound: TCP 443 from 0.0.0.0/0 and TCP 22 from 203.0.113.0/24; Outbound: TCP 443 to 0.0.0.0/0 only

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot