Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A financial institution is deploying a new application to a public cloud provider. Due to stringent regulatory requirements (e.g., PCI DSS), network traffic between different security zones within the cloud environment (e.g., web tier, application tier, database tier) must be strictly isolated and inspected. Which cloud network security component provides granular, stateful inspection and filtering of traffic between these zones?
- ACloud WAF (Web Application Firewall)
- BSecurity Group
- CVirtual Network Gateway
- DNetwork Access Control List (NACL)
Show answer & explanationAnswer & explanation
Correct answer: B. Security Group
Security Groups provide stateful packet filtering at the instance level (or network interface level) within a Virtual Private Cloud (VPC). They allow granular control over inbound and outbound traffic for specific instances or groups of instances, making them ideal for isolating and securing application tiers.
Why the other options are wrong
- A. A Cloud WAF protects web applications from common web exploits (e.g., SQL injection, XSS) and operates at the application layer, but does not provide generalized stateful packet filtering between internal network zones.
- C. A Virtual Network Gateway is typically used for connecting on-premises networks to the cloud VPC or for inter-VPC communication, not for granular internal zone segmentation.
- D. NACLs are stateless, operate at the subnet level, and are less granular than Security Groups for instance-level traffic control.
Security Group (Cloud)
A virtual firewall that controls inbound and outbound traffic for one or more network interfaces or instances in a cloud environment.
- Stateful packet filtering.
- Operates at the instance/ENI level.
- Allows granular control over ports and protocols.
- Acts as a micro-segmentation tool within a VPC.
Memory trick: Security Groups: Guarding instances, port by port.