Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium
A cloud operations team is implementing a new virtual network for a highly sensitive application. They are concerned about potential network-based attacks where malicious actors might forge source IP addresses to bypass security controls or impersonate legitimate services. Which cloud network security feature specifically protects against this type of attack within a Virtual Private Cloud (VPC)?
- ANetwork Access Control Lists (NACLs)
- BVPC Flow Logs
- CSource/Destination Check or IP Spoofing Protection
- DSecurity Groups
Show answer & explanationAnswer & explanation
Correct answer: C. Source/Destination Check or IP Spoofing Protection
Cloud providers offer features like 'Source/Destination Check' (AWS) or built-in IP spoofing protection which prevent instances from sending or receiving traffic with a source or destination IP address that is not its own. This directly mitigates IP spoofing attacks.
Why the other options are wrong
- A. NACLs are stateless firewalls operating at the subnet level, filtering traffic based on IP, port, and protocol, but also don't directly prevent IP spoofing.
- B. VPC Flow Logs capture information about IP traffic going to and from network interfaces, useful for monitoring and forensics, but not for preventing spoofing in real-time.
- D. Security Groups are stateful firewalls that control traffic based on IP, port, and protocol, but typically don't inherently prevent IP spoofing.
Cloud IP Spoofing Protection
A cloud network security feature (e.g., Source/Destination Check) that prevents virtual machines or network interfaces from sending or receiving traffic with forged source or destination IP addresses.
- Ensures network traffic originates from and is destined for legitimate IPs.
- Protects against man-in-the-middle and unauthorized access attempts.
- Often a default setting on cloud network interfaces.
Memory trick: Spoofing stopped, source confirmed.