CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A cloud architect is designing a secure network for a multi-tenant SaaS application hosted on a public cloud provider. The application processes sensitive customer data, and strict isolation between tenants is paramount. Which network architecture component is MOST effective in providing granular, logical separation of network traffic and resources for each tenant within the shared cloud infrastructure?
- AVirtual Local Area Network (VLAN)
- BPublic IP addresses
- CNetwork Security Groups (NSG)
- DVirtual Private Cloud (VPC)
Show answer & explanationAnswer & explanation
Correct answer: D. Virtual Private Cloud (VPC)
A Virtual Private Cloud (VPC) provides a logically isolated section of a public cloud, allowing organizations to define their own virtual network topology, including IP address ranges, subnets, route tables, and network gateways. This is the foundational component for achieving strict tenant isolation in a multi-tenant cloud environment.
Why the other options are wrong
- A. VLANs are a traditional on-premises networking concept for segmenting a physical network. While analogous in function, they are not the primary or most effective mechanism for logical isolation within a public cloud provider's infrastructure.
- B. Public IP addresses are used for external connectivity but do not provide any inherent network isolation or segmentation capabilities within the cloud environment.
- C. Network Security Groups (or Security Group rules) are stateful firewalls that control inbound and outbound traffic for individual instances or network interfaces within a VPC, providing granular packet filtering but not the overarching network isolation of a VPC.
Virtual Private Cloud (VPC)
A VPC is a private, isolated section of a public cloud where users can launch cloud resources in a virtual network they define. It provides logical isolation from other virtual networks in the cloud, even though it shares underlying physical infrastructure.
- Logically isolated network within a public cloud.
- Users define IP ranges, subnets, route tables, network gateways.
- Enhances security and control over cloud resources.
- Essential for multi-tenant architectures and regulatory compliance.
Memory trick: Each tenant gets their own private, virtual apartment building in the cloud city.