Courseiva
hardMultiple Choice

CCSP Least privilege Practice Question

Exhibit

{
  "SecurityGroup": {
    "GroupName": "sg-web",
    "IngressRules": [
      { "Protocol": "TCP", "PortRange": "443", "SourceCIDR": "10.0.0.0/8" },
      { "Protocol": "TCP", "PortRange": "22", "SourceCIDR": "0.0.0.0/0" }
    ],
    "EgressRules": [
      { "Protocol": "TCP", "PortRange": "443", "DestinationCIDR": "0.0.0.0/0" }
    ]
  }
}

Refer to the exhibit. A cloud security administrator is reviewing the following network firewall rule configuration associated with a web server instance. What security best practice is being violated?

⚠ Common exam trap

ISC2 often tests the misconception that allowing inbound HTTPS from any source is a violation, but for a public web server, this is correct; the trap is confusing the need for open HTTPS with the need to restrict administrative protocols like SSH.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inbound SSH should not be allowed from any source.

Allowing inbound SSH (TCP port 22) from any source (0.0.0.0/0) violates the security best practice of least privilege. SSH should only be permitted from specific administrative IP ranges or bastion hosts to prevent unauthorized access and brute-force attacks. In a cloud environment, network firewall rules should restrict SSH to known management networks, not the entire internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Outbound traffic should be allowed to any destination.

    Why it's wrong here

    Allowing outbound traffic to any destination removes egress filtering, so a compromised web server can reach command-and-control infrastructure or exfiltrate data unchallenged. Egress rules should restrict destinations to required update and API endpoints. Permitting all outbound traffic suits trusted, isolated development sandboxes where connectivity troubleshooting matters more than containment.

  • ✓

    Inbound SSH should not be allowed from any source.

    Why this is correct

    Allowing SSH from 0.0.0.0/0 exposes the management port to the entire internet, enabling brute-force and exploitation attempts. Administrative access should be restricted to trusted CIDR ranges or a bastion, so the any-source inbound rule violates least-privilege network exposure.

  • ✗

    Inbound HTTPS should be allowed from any source.

    Why it's wrong here

    Allowing HTTPS from any source exposes the web server to the whole internet rather than the intended clients, defeating least privilege. The rule should restrict sources to known ranges. Any-source HTTPS suits public sites deliberately serving anonymous global traffic.

  • ✗

    Security groups should not be used for web servers.

    Why it's wrong here

    Security groups are the standard mechanism for controlling traffic to web servers; the violation lies in the rule's overly broad source range, not in using a security group. Security groups suit precisely this filtering role for any instance type.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.