🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 13 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company hosts development and production microservices on Amazon EC2 in the same /16 VPC subnet that shares security groups, letting developers reach production databases. You need strong logical isolation between the environments while still allowing limited CI/CD ports from development into production, with minimal cost and administration. Which approach best meets these requirements?

  • Keep all instances in the current subnet but assign distinct security groups to dev and prod and deny all inter-group traffic except the CI/CD ports.

  • Keep both environments in the same subnet but deploy AWS Network Firewall between them to filter all traffic except the CI/CD ports.

  • Move development instances to a new subnet within the existing VPC and attach a dedicated network ACL that blocks all traffic except the CI/CD ports.

  • Create separate VPCs for development and production, connect them with a VPC peering connection, and use route tables and security groups to allow only the required CI/CD ports.

ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot