ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A company is moving its financial reporting application to a public IaaS provider. A security policy states that:

  • All human administrators must use multi-factor authentication (MFA).
  • No long-lived secret keys may be stored in source-code repositories or build pipelines. Currently, the on-premises CI/CD server uploads application images to the cloud by exporting an access key and secret key that belong to an administrator-level account. Which change will BEST satisfy the policy with minimal modification to the existing pipeline scripts?
  • Store the existing administrator access key and secret key in a managed secrets vault service and have the pipeline retrieve them programmatically during each run.

  • Replace the existing administrator account with a new IAM user that enforces virtual MFA and use its access key and secret key in the pipeline.

  • Create a dedicated IAM role for the upload task and have the pipeline call the cloud provider's Security Token Service to assume that role and obtain temporary credentials at run time.

  • Keep the current access key but enable an automatic rotation policy so that the key pair is changed every 30 days and updated in the pipeline variables.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot