ISC2 Certified Cloud Security Professional (CCSP) Practice Question

An organization uses a public IaaS provider that exposes its management plane through both a web console and a REST API. The same identity store is leveraged for interactive logins and for programmatic access keys consumed by the company's CI/CD pipeline. To minimize the blast radius if any one credential set is compromised-while still allowing the pipeline to deploy new virtual machines automatically-which of the following controls BEST addresses the management-plane risk?

  • Provision a dedicated service identity with only the required API permissions and disable its ability to sign in to the web console.

  • Configure host-based firewalls on every virtual machine to accept management traffic only from corporate IP addresses.

  • Force all automation traffic through an MFA-protected bastion host before it reaches the provider endpoints.

  • Raise the provider's default service quotas for the automation account to prevent API throttling during deployments.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot