(ISC)2
CCSP · Question #870
Traditional firewalls mainly protect north-south traffic. Which solution is most appropriate for isolating east-west traffic (server-to-server) inside a cloud?
The correct answer is C. Host-based firewall or micro-segmentation. East-west traffic (VM to VM in the same data center) needs a solution like micro-segmentation or host firewalls that control traffic on each host. Traditional firewalls or WAFs focus on north-south (in/out of network).
Submitted by javi_es· Apr 18, 2026Cloud Platform & Infrastructure Security
Question
Traditional firewalls mainly protect north-south traffic. Which solution is most appropriate for isolating east-west traffic (server-to-server) inside a cloud?
Options
- ANetwork-based intrusion detection system (NIDS)
- BVirtual private network (VPN)
- CHost-based firewall or micro-segmentation
- DWeb Application Firewall (WAF)
How the community answered
(19 responses)- A5% (1)
- B5% (1)
- C79% (15)
- D11% (2)
Explanation
East-west traffic (VM to VM in the same data center) needs a solution like micro-segmentation or host firewalls that control traffic on each host. Traditional firewalls or WAFs focus on north-south (in/out of network).
Topics
#Micro-segmentation#East-west traffic#Cloud network security#Host-based firewalls
Community Discussion
No community discussion yet for this question.