Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityEasy
A company is migrating its on-premises applications to a public cloud provider. They need to ensure that network traffic between their on-premises data center and the cloud environment is encrypted and secure, without exposing internal IP addresses to the public internet. Which cloud security technology best addresses this requirement?
- AVirtual Private Network (VPN)
- BSecurity Information and Event Management (SIEM)
- CCloud Access Security Broker (CASB)
- DWeb Application Firewall (WAF)
Show answer & explanationAnswer & explanation
Correct answer: A. Virtual Private Network (VPN)
A VPN establishes an encrypted tunnel between the on-premises network and the cloud, securing traffic and allowing internal IP addresses to traverse the public internet privately, fulfilling both requirements.
Why the other options are wrong
- B. SIEMs collect and analyze security logs for threat detection, not for establishing secure network connectivity.
- C. CASBs focus on cloud application security, data governance, and threat protection for SaaS/PaaS, not site-to-site network encryption.
- D. WAFs protect web applications from common attacks, operating at the application layer, not for general network encryption between sites.
Virtual Private Network (VPN)
A technology that creates a secure, encrypted connection over a less secure network, such as the internet.
- Establishes a private network over a public network.
- Encrypts data transmitted between endpoints.
- Used for remote access and site-to-site connectivity.
Memory trick: Cloud connections need a secure tunnel to keep secrets safe.