🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 8 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your organization is redesigning its on-prem network for a new three-tier app. Policy says only HTTPS can reach the web tier, the web tier initiates TCP 8443 to the app tier, and the database tier accepts MySQL only from the app tier. Which firewall deployment best enforces these rules inside the data center while avoiding extra hardware?

  • Deploy host-based firewalls on every server and centrally manage the rules with configuration-management tools.

  • Place a dedicated next-generation application firewall between each pair of tiers, adding a new appliance whenever a tier is created.

  • Install a stateful Layer 3/4 firewall at the network core and use VLAN sub-interfaces with access control lists to filter inter-tier traffic.

  • Implement a hypervisor-based distributed firewall that applies stateful policies to east-west traffic between virtual machines in each tier.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot