CompTIA Cloud+ (CV0-004)SecurityEasy

A cloud administrator is configuring access to a highly sensitive database containing customer financial records. The database is hosted in a public cloud environment. To minimize the attack surface and ensure that only authorized services within the same virtual network can access the database, which security measure should be implemented?

  1. AUtilizing private endpoints or service endpoints for database access.
  2. BConfiguring multi-factor authentication (MFA) for database user accounts.
  3. CImplementing a Web Application Firewall (WAF) in front of the database.
  4. DEncrypting all data at rest and in transit using customer-managed keys.
Show answer & explanation

Correct answer: A. Utilizing private endpoints or service endpoints for database access.

Private endpoints or service endpoints allow services within the same virtual network to connect to platform-as-a-service (PaaS) resources like databases privately, without traversing the public internet. This significantly reduces the attack surface and enhances security for sensitive data.

Why the other options are wrong

  • B. MFA strengthens user authentication but does not address the network-level access control for services connecting to the database.
  • C. A WAF protects web applications from common web exploits, but it does not restrict network access to a database from within a virtual network.
  • D. Encryption is crucial for data protection but does not directly control network-level access to the database from within the cloud environment.

Private/Service Endpoints

Network interfaces that connect cloud services privately to a virtual network, preventing traffic from traversing the public internet.

  • Enhances security by isolating traffic.
  • Reduces attack surface for cloud services.
  • Requires services to be within the same virtual network.

Memory trick: Private roads for private data, no public highways.

More Security questions