
EC-CouncilCloud Security Essentials
Domain 4Objective 3
Network Access Control Lists (NACLs) and Network Security Groups (NSG) CSE Practice Questions (Page 1)
Part of the Network Security in the Cloud domain, which makes up ~10% of our current practice bank.
18questions here
4free pages
6concepts
Questions 1–5
- 1
A company is migrating a legacy application to the cloud. The application requires that a specific set of IP addresses (from a partner) be able to access a management interface on a VM. The security team wants to ensure that even if the VM's OS firewall is compromised, the network layer still blocks unauthorized access. They also want to minimize the number of rules to manage. Which approach should they take?
Select an answer first - 2
A security team wants to implement defense-in-depth for a subnet containing web servers. Which combination of network security controls is a best practice?
Select an answer first - 3
What is the default behavior of an NSG when no rules match?
Select an answer first - 4
A security team is implementing a defense-in-depth strategy for a three-tier application. They want to ensure that even if an NSG is misconfigured on a particular instance, the subnet-level controls still prevent unauthorized traffic. Which approach best achieves this?
Select an answer first - 5
At which level are NACLs typically applied?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.