Question 1
Q1A financial services company is deploying a three-tier web application in OCI. The compliance team has mandated that network traffic between the web and application tiers must be strictly controlled, allowing only specific TCP ports. Additionally, the security posture must be easily auditable and scalable as more application servers are added. Which OCI networking security feature should be used to meet these requirements most effectively?
Show answer & explanation
Correct answer: B
Network Security Groups (NSGs) are the optimal choice here. They operate at the VNIC level, allowing for granular, stateful firewall rules to be defined for a specific set of resources (like the application tier) regardless of the subnet they reside in. This application-centric model is more scalable and easier to audit than subnet-wide Security Lists when managing traffic between specific application tiers.