ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
An e-commerce company plans to enable a new feature in its AWS CloudFormation deployment pipeline that automatically updates security groups whenever a new microservice is deployed. The change will allow the pipeline to generate and attach rules without human review. You are preparing the security impact analysis for the Change Advisory Board. Which potential risk deserves the greatest scrutiny before the change is approved?
Tagging conventions applied by the pipeline could overwrite existing cost allocation tags on security groups.
Automatically generated rules could unintentionally widen inbound access and expose internal services to the internet.
New security groups created in multiple AWS Regions could increase monthly Network ACL charges.
The additional CloudFormation tasks could lengthen stack creation, delaying deployments during peak hours.
The most significant security concern is that automatically generated security-group rules might unintentionally broaden inbound access, exposing previously internal resources directly to the internet. Such exposure can compromise confidentiality, integrity, and availability and is difficult to detect once stacks are live. Longer deployment times, higher regional costs, or overwritten cost-allocation tags are operational or financial issues; they do not present the same level of immediate security risk posed by inadvertent open network access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are AWS security groups?
Open an interactive chat with Bash
How can automatically generated rules widen inbound access unintentionally?
Open an interactive chat with Bash
What are potential safeguards against security group misconfigurations?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .