CompTIA Cloud+ (CV0-004)SecurityMedium
A company is migrating its on-premises applications to a public cloud. As part of the security architecture, all network traffic between the cloud environment and the internet must be inspected for malicious activity and policy violations before reaching virtual machines. Which cloud security service should be implemented to fulfill this requirement most effectively?
- AData Loss Prevention (DLP)
- BSecurity Information and Event Management (SIEM)
- CNext-Generation Firewall (NGFW)
- DCloud Access Security Broker (CASB)
Show answer & explanationAnswer & explanation
Correct answer: C. Next-Generation Firewall (NGFW)
A Next-Generation Firewall (NGFW) is specifically designed to inspect network traffic at deep packet levels, identify malicious activity, and enforce security policies before traffic reaches its destination. This directly addresses the requirement for inspecting all internet-bound traffic before it reaches VMs.
Why the other options are wrong
- A. DLP focuses on preventing sensitive data from leaving the organization's control, but it's not primarily designed for comprehensive inspection and blocking of all malicious network traffic.
- B. SIEM collects and analyzes security logs and events, but it does not actively inspect and block network traffic in real-time.
- D. A CASB focuses on enforcing security policies on cloud applications and data, often for SaaS, but typically doesn't provide granular, inline inspection of all network traffic at the perimeter.
Next-Generation Firewall (NGFW)
An advanced firewall that combines traditional firewall functions with additional capabilities like deep packet inspection, intrusion prevention, and application awareness.
- Deep packet inspection
- Intrusion prevention system (IPS) capabilities
- Application-level control
Memory trick: NGFW is the smart gatekeeper for all cloud network traffic.