hardMultiple Choice
CCSP Least privilege Practice Question
Exhibit
{
"SecurityGroup": {
"GroupName": "sg-web",
"IngressRules": [
{ "Protocol": "TCP", "PortRange": "443", "SourceCIDR": "10.0.0.0/8" },
{ "Protocol": "TCP", "PortRange": "22", "SourceCIDR": "0.0.0.0/0" }
],
"EgressRules": [
{ "Protocol": "TCP", "PortRange": "443", "DestinationCIDR": "0.0.0.0/0" }
]
}
}Refer to the exhibit. A cloud security administrator is reviewing the following network firewall rule configuration associated with a web server instance. What security best practice is being violated?
⚠ Common exam trap
ISC2 often tests the misconception that allowing inbound HTTPS from any source is a violation, but for a public web server, this is correct; the trap is confusing the need for open HTTPS with the need to restrict administrative protocols like SSH.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inbound SSH should not be allowed from any source.
Allowing inbound SSH (TCP port 22) from any source (0.0.0.0/0) violates the security best practice of least privilege. SSH should only be permitted from specific administrative IP ranges or bastion hosts to prevent unauthorized access and brute-force attacks. In a cloud environment, network firewall rules should restrict SSH to known management networks, not the entire internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Outbound traffic should be allowed to any destination.
Why it's wrong here
Allowing outbound traffic to any destination removes egress filtering, so a compromised web server can reach command-and-control infrastructure or exfiltrate data unchallenged. Egress rules should restrict destinations to required update and API endpoints. Permitting all outbound traffic suits trusted, isolated development sandboxes where connectivity troubleshooting matters more than containment.
- ✓
Inbound SSH should not be allowed from any source.
Why this is correct
Allowing SSH from 0.0.0.0/0 exposes the management port to the entire internet, enabling brute-force and exploitation attempts. Administrative access should be restricted to trusted CIDR ranges or a bastion, so the any-source inbound rule violates least-privilege network exposure.
- ✗
Inbound HTTPS should be allowed from any source.
Why it's wrong here
Allowing HTTPS from any source exposes the web server to the whole internet rather than the intended clients, defeating least privilege. The rule should restrict sources to known ranges. Any-source HTTPS suits public sites deliberately serving anonymous global traffic.
- ✗
Security groups should not be used for web servers.
Why it's wrong here
Security groups are the standard mechanism for controlling traffic to web servers; the violation lies in the rule's overly broad source range, not in using a security group. Security groups suit precisely this filtering role for any instance type.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.