Which of the following services would restrict connectivity - CompTIA CLO-002

Question

Which of the following services would restrict connectivity to cloud resources?

Answers
  1. correct
Explanation

Correct Answer: A. Security lists

Security lists are specifically designed for cloud environments to restrict or allow connectivity by applying ingress (incoming) and egress (outgoing) rules. They are tightly integrated into cloud platforms and allow granular control over access to resources.

  • Why it's correct:
    Security lists directly manage traffic restrictions to cloud resources. They operate at the subnet or virtual machine (VM) level in cloud environments. Rules can block or permit traffic based on IP addresses, port numbers, and protocols.
    • For example, a security list in Oracle Cloud Infrastructure (OCI) might allow HTTP traffic (port 80) from the internet but block all other access.

Why others are incorrect

Firewall (Incorrect)

Firewalls are broader in scope compared to security lists. While they also control traffic, firewalls are generally applied at a network perimeter or between systems, often requiring additional configuration in cloud setups.

  • Why it's incorrect:
    Firewalls are not exclusive to cloud environments and often serve as an external security layer. While they can restrict connectivity, they are not specifically integrated with cloud resources like security lists. Additionally, they are more suited to complex scenarios such as protecting entire networks.

VPN (Virtual Private Network) (Incorrect)

A VPN provides secure connectivity between devices or networks by creating an encrypted tunnel over public networks. Its primary role is to ensure data security and confidentiality during transmission.

  • Why it's incorrect:
    VPNs enable connectivity and secure data transfer, but they do not restrict or manage traffic. For example, a VPN can allow a remote worker to securely connect to a cloud network, but it won't control which specific services or ports can be accessed.

Intrusion Detection System (IDS) (Incorrect)

An IDS is a monitoring tool that analyzes network traffic to identify potential threats or malicious activity. It provides alerts but does not actively block or allow traffic.

  • Why it's incorrect:
    IDS systems are passive tools. While they help detect suspicious activity, they do not restrict connectivity. For example, an IDS might detect a brute-force login attempt on a cloud server and send an alert, but it won’t prevent the attempt itself.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered