Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityEasy

A cloud administrator is configuring security for a new set of virtual machines (VMs) deployed in a public cloud. The administrator needs to ensure that only specific, authorized network traffic can reach these VMs, while all other inbound traffic is blocked by default. Which of the following cloud security controls should be primarily used to achieve this objective?

  1. AData Loss Prevention (DLP) solutions
  2. BHost-based Intrusion Detection Systems (HIDS)
  3. CWeb Application Firewalls (WAF)
  4. DSecurity Groups or Network Access Control Lists (NACLs)
Show answer & explanation

Correct answer: D. Security Groups or Network Access Control Lists (NACLs)

Security Groups and Network Access Control Lists (NACLs) are fundamental cloud network security controls used to filter traffic at the virtual network level, allowing administrators to define inbound and outbound rules based on IP addresses, ports, and protocols. They effectively block unwanted traffic by default.

Why the other options are wrong

  • A. DLP solutions focus on preventing sensitive data from leaving the organization's control, not on filtering inbound network traffic to VMs.
  • B. HIDS monitors for suspicious activity on individual VMs but does not block traffic at the network perimeter.
  • C. WAFs protect web applications from common web-based attacks but are not a general-purpose network traffic filter for all VM traffic.

Security Groups/NACLs

Cloud-native virtual firewall services that control inbound and outbound network traffic for virtual machines or subnets based on rules.

  • Filter traffic based on IP, port, protocol.
  • Act as a virtual firewall.
  • Configurable at VM or subnet level.

Memory trick: NAC and Security Groups act as traffic cops for your cloud VMs.

More Cloud Platform and Infrastructure Security questions