Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityEasy

A cloud security engineer is designing a secure network architecture for a new application deployed in a public cloud. The application requires strict isolation between its different tiers (web, application, database) and needs to control traffic flow based on IP addresses and ports. Which cloud security technology is most appropriate for enforcing these granular network segmentation policies within the virtual private cloud?

  1. ADistributed Denial of Service (DDoS) Protection
  2. BCloud Access Security Broker (CASB)
  3. CWeb Application Firewall (WAF)
  4. DSecurity Group
Show answer & explanation

Correct answer: D. Security Group

Security Groups provide stateful packet filtering at the instance level, allowing granular control over inbound and outbound traffic based on IP addresses, ports, and protocols, which is ideal for segmenting application tiers.

Why the other options are wrong

  • A. DDoS protection mitigates large-scale denial-of-service attacks, not internal network segmentation.
  • B. CASBs focus on cloud service access, data governance, and compliance, not network packet filtering.
  • C. WAFs protect against web application-specific attacks, not general network segmentation.

Security Group (Cloud)

A virtual firewall that controls inbound and outbound traffic for one or more virtual instances within a cloud environment.

  • Operates at the instance level, not subnet.
  • Stateful packet filtering: automatically allows return traffic.
  • Defines rules based on IP addresses, port numbers, and protocols.

Memory trick: Think of Security Groups as bouncers for your cloud servers, checking IDs and entry passes.

More Cloud Security questions