🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 7 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company is deploying a 3-tier web app in a single VPC. The security policy is:

  1. Public-subnet web servers must accept only HTTPS (TCP 443) from the internet.
  2. The web tier may reach the application tier only on TCP 8080.
  3. Exploitation attempts against the web servers must be detected within minutes without installing agents on each instance.

Which approach satisfies all requirements with minimal operational effort?

  • Use the same security group for both tiers that allows inbound TCP 443 and 8080; enable Amazon Macie to detect malicious activity against the web servers.

  • Deploy a third-party next-generation firewall appliance from AWS Marketplace in a dedicated subnet to filter traffic; forward its logs to CloudWatch for alerting.

  • Create separate security groups for web and application instances; allow inbound 0.0.0.0/0 TCP 443 to the web-tier group and only TCP 8080 from the web-tier group to the application-tier group. Enable Amazon GuardDuty in the account for near-real-time threat detection.

  • Attach stateless network ACLs to the public and private subnets that allow TCP 443 and TCP 8080 respectively, and configure AWS Config rules to alert on unauthorized traffic.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot