🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A two-tier web application runs on EC2 instances in two private subnets, each in a different Availability Zone. Security engineers must insert a third-party IDS virtual appliance from AWS Marketplace to inspect all outbound internet traffic. The solution must remain available if an AZ fails, require only a route-table change (no instance changes), and let the team add appliance capacity as traffic grows. Which deployment meets these goals?

  • Deploy two IDS appliances in separate Availability Zones behind an Application Load Balancer and point each private subnet's default route (0.0.0.0/0) at the ALB.

  • Place multiple IDS appliance instances in each Availability Zone behind a Gateway Load Balancer, create Gateway Load Balancer endpoints in the private subnets, and set each subnet's default route to its local endpoint.

  • Enable VPC Flow Logs for the private subnets and forward the logs to an EC2-hosted IDS appliance for offline inspection.

  • Launch one IDS appliance in a dedicated public subnet and configure every EC2 instance to use the appliance's network interface as its default gateway.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot