mediumMultiple Choice
CCSP Practice Question: A healthcare organization has deployed a…
A healthcare organization has deployed a cloud-based application that handles protected health information (PHI). The application runs on virtual machines in a virtual private cloud (VPC). The security team has implemented security groups to control traffic to the VMs. Recently, an external penetration test revealed that a web server VM is accessible from the internet on port 22 (SSH) from any IP address (0.0.0.0/0). The security team also discovered that the SSH key pair used for the web server was created with a weak algorithm (1024-bit RSA). The team needs to remediate these issues without causing downtime for the application. Additionally, the application logs must be sent to a centralized logging solution that is encrypted in transit and at rest. Which combination of actions should the security team take?
⚠ Common exam trap
ISC2 often tests the distinction between security by obscurity (e.g., changing ports) and actual security controls (e.g., restricting IPs and using strong keys), leading candidates to pick options that seem quick but fail compliance requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict inbound SSH access to only a bastion host's IP address, generate a new 2048-bit RSA key pair, configure the application to send logs via TLS to a centralized logging service, and enable server-side encryption for the logging bucket.
It addresses both critical vulnerabilities without downtime: restricting SSH to a bastion host's IP eliminates internet-wide exposure, and generating a new 2048-bit RSA key pair replaces the weak 1024-bit key. For logging, TLS ensures encryption in transit, and server-side encryption for the logging bucket ensures encryption at rest, meeting compliance requirements for PHI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restrict inbound SSH access to only a bastion host's IP address, generate a new 2048-bit RSA key pair, configure the application to send logs via TLS to a centralized logging service, and enable server-side encryption for the logging bucket.
Why this is correct
Narrowing the security group to the bastion host's address removes internet-wide SSH exposure, and regenerating the key pair at 2048-bit RSA replaces the weak algorithm. TLS transport plus server-side encryption satisfies the encrypted-in-transit and at-rest logging requirement without downtime.
- ✗
Implement a VPN connection for all administrative access, keep the existing key pair, and use a third-party logging tool with TLS.
Why it's wrong here
The 1024-bit RSA key pair remains in place, so the weak-algorithm finding is unremediated; a VPN only narrows who can reach port 22. VPN-restricted administrative access is the right control when the key strength itself already meets policy.
- ✗
Change the SSH port to a non-standard port, keep the existing key pair, and enable logging to a cloud storage bucket without encryption.
Why it's wrong here
Security through obscurity: moving SSH to another port leaves the 0.0.0.0/0 exposure and the weak 1024-bit RSA key pair intact, and the unencrypted bucket breaches the at-rest requirement. Port relocation is defensible only alongside key rotation and source restriction.
- ✗
Disable SSH access entirely and use a serial console for administration, keep the existing key pair, and send logs via plaintext syslog to a logging server.
Why it's wrong here
Plaintext syslog violates the encryption-in-transit requirement, and the weak 1024-bit RSA key pair is retained. A serial console is a valid out-of-band administrative path when console access is the only management channel available and logging is separately encrypted.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.