CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a secure private cloud environment for a government agency. The agency requires strict network isolation between different departments and projects, ensuring that traffic from one department cannot inadvertently or maliciously reach resources belonging to another, even within the same physical infrastructure. Which cloud networking construct is most appropriate for achieving this granular network segmentation and isolation?

  1. AContent Delivery Network (CDN)
  2. BSoftware-Defined Wide Area Network (SD-WAN)
  3. CVirtual Private Cloud (VPC)
  4. DPublic Cloud Instance
Show answer & explanation

Correct answer: C. Virtual Private Cloud (VPC)

A Virtual Private Cloud (VPC) provides a logically isolated section of a cloud provider's network where users can launch resources in a virtual network that they define, allowing for strict segmentation and control over network traffic for different departments or projects.

Why the other options are wrong

  • A. A CDN is used for content delivery and caching, not for internal network segmentation and isolation.
  • B. SD-WAN optimizes WAN traffic and connectivity between sites, but it's not the primary construct for internal cloud network segmentation.
  • D. A Public Cloud Instance is a single virtual machine, not a network construct for overall isolation.

Virtual Private Cloud (VPC)

A logically isolated virtual network within a cloud provider's infrastructure, allowing users to define and control their own virtual networking environment, including IP address ranges, subnets, route tables, and network gateways.

  • Provides network isolation and segmentation.
  • Users have control over their virtual network topology.
  • Enables secure connectivity and resource grouping.

Memory trick: VPC: Your 'Virtual Private Castle' in the cloud.

More Security Architecture questions