
EC-CouncilCloud Security Essentials
Domain 4Objective 3
Network Access Control Lists (NACLs) and Network Security Groups (NSG) CSE Practice Questions (Page 4)
Part of the Network Security in the Cloud domain, which makes up ~10% of our current practice bank.
18questions here
4free pages
6concepts
Questions 16–18
- 16
A company is deploying a multi-tier web application in a cloud VPC. The web tier must be reachable from the internet on port 443, the application tier should only accept traffic from the web tier, and the database tier should only accept traffic from the application tier. The security team wants to enforce these rules at the subnet boundary as a first line of defense, while also allowing per-instance customization. Which combination of controls should they use?
Select an answer first - 17
Which statement correctly describes a key difference between NACLs and NSGs?
Select an answer first - 18
A startup is deploying a three-tier application in a single VPC. The web tier must be reachable from the internet on port 443. The application tier should only accept traffic from the web tier, and the database tier should only accept traffic from the application tier. The security team wants to enforce these rules at the subnet boundary as an additional layer of defense beyond instance-level controls. Which configuration should the team use?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.