CompTIA Cloud+ (CV0-004)SecurityEasy
A cloud administrator is configuring access to a highly sensitive database containing customer financial records. The database is hosted in a public cloud environment. To minimize the attack surface and ensure that only authorized services within the same virtual network can access the database, which security measure should be implemented?
- AUtilizing private endpoints or service endpoints for database access.
- BConfiguring multi-factor authentication (MFA) for database user accounts.
- CImplementing a Web Application Firewall (WAF) in front of the database.
- DEncrypting all data at rest and in transit using customer-managed keys.
Show answer & explanationAnswer & explanation
Correct answer: A. Utilizing private endpoints or service endpoints for database access.
Private endpoints or service endpoints allow services within the same virtual network to connect to platform-as-a-service (PaaS) resources like databases privately, without traversing the public internet. This significantly reduces the attack surface and enhances security for sensitive data.
Why the other options are wrong
- B. MFA strengthens user authentication but does not address the network-level access control for services connecting to the database.
- C. A WAF protects web applications from common web exploits, but it does not restrict network access to a database from within a virtual network.
- D. Encryption is crucial for data protection but does not directly control network-level access to the database from within the cloud environment.
Private/Service Endpoints
Network interfaces that connect cloud services privately to a virtual network, preventing traffic from traversing the public internet.
- Enhances security by isolating traffic.
- Reduces attack surface for cloud services.
- Requires services to be within the same virtual network.
Memory trick: Private roads for private data, no public highways.