CompTIA Cloud+ (CV0-004)SecurityEasy
A cloud administrator is tasked with implementing a network security solution that restricts inbound and outbound traffic to specific virtual machines based on predefined rules. The solution must be highly granular and operate at the instance level within a public cloud environment. Which of the following security constructs is MOST appropriate for this requirement?
- ANetwork Security Group (NSG)
- BWeb Application Firewall (WAF)
- CVirtual Private Network (VPN)
- DCloud Access Security Broker (CASB)
Show answer & explanationAnswer & explanation
Correct answer: A. Network Security Group (NSG)
Network Security Groups (NSGs) allow administrators to filter network traffic to and from virtual machine instances, providing granular control at the instance level.
Why the other options are wrong
- B. WAFs protect web applications from common web-based attacks, operating at the application layer, not for general instance-level traffic control.
- C. VPNs establish secure connections between networks or to a network, not for instance-level traffic filtering.
- D. CASBs enforce security policies for cloud services and applications, primarily focusing on data visibility, threat protection, and compliance, not instance-level network filtering.
Network Security Group (NSG)
A virtual firewall that controls inbound and outbound network traffic to virtual machines or subnets within a cloud environment.
- Operates at the instance or subnet level.
- Defines rules for IP addresses, ports, and protocols.
- Is stateful, meaning it tracks connections.
Memory trick: NSG is like a personal bouncer for your cloud VMs.