nerdexam
(ISC)2

CCSP · Question #870

Traditional firewalls mainly protect north-south traffic. Which solution is most appropriate for isolating east-west traffic (server-to-server) inside a cloud?

The correct answer is C. Host-based firewall or micro-segmentation. East-west traffic (VM to VM in the same data center) needs a solution like micro-segmentation or host firewalls that control traffic on each host. Traditional firewalls or WAFs focus on north-south (in/out of network).

Submitted by javi_es· Apr 18, 2026Cloud Platform & Infrastructure Security

Question

Traditional firewalls mainly protect north-south traffic. Which solution is most appropriate for isolating east-west traffic (server-to-server) inside a cloud?

Options

  • ANetwork-based intrusion detection system (NIDS)
  • BVirtual private network (VPN)
  • CHost-based firewall or micro-segmentation
  • DWeb Application Firewall (WAF)

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    79% (15)
  • D
    11% (2)

Explanation

East-west traffic (VM to VM in the same data center) needs a solution like micro-segmentation or host firewalls that control traffic on each host. Traditional firewalls or WAFs focus on north-south (in/out of network).

Topics

#Micro-segmentation#East-west traffic#Cloud network security#Host-based firewalls

Community Discussion

No community discussion yet for this question.

Full CCSP Practice