🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company is migrating its on-premises two-node next-generation firewall (NGFW) cluster to AWS. Security policy mandates that all east-west traffic between private subnets in a VPC must continue to be inspected by the same vendor's firewall engine. The solution must support automatic scaling across multiple Availability Zones and minimize ongoing operational maintenance. Which approach best meets these requirements?

  • Deploy the vendor's virtual firewall instances as an Auto Scaling group behind an AWS Gateway Load Balancer, create Gateway Load Balancer endpoints in each private subnet, and update route tables to send inter-subnet traffic through the load balancer.

  • Attach AWS WAF web ACLs to the Application Load Balancer that fronts the VPC and configure rules to filter malicious traffic between subnets.

  • Replace the NGFW with stateless network ACLs that permit only required ports between subnets and enable VPC Flow Logs for monitoring.

  • Enable AWS Network Firewall in the VPC, import the vendor's signature set, and direct subnet route tables to the firewall endpoint.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot