ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During a security assessment you learn that every cloud administrator in your organization uses the same long-lived API access key, which is configured with full management-plane permissions across all projects. The CIO asks you to recommend the FIRST control to reduce the likelihood and blast radius of a management-plane credential compromise while still allowing administrators to perform their duties. Which action meets this goal?
Install host-based intrusion detection agents on every virtual machine in each project.
Replace the shared key with individual administrator identities assigned least-privilege roles via the provider's IAM/RBAC service.
Enable server-side encryption on all object storage buckets used by the projects.
Restrict the cloud provider's API endpoint to a private IP range reachable only through a site-to-site VPN.
Using a single, highly privileged key violates the principles of least privilege and accountability. Replacing it with individual identities mapped to narrowly scoped roles through the provider's IAM service immediately removes shared credentials, enforces least-privilege access, and provides auditable attribution for each action on the management plane. Encryption of storage buckets and host-based IDS protect the data or compute planes rather than the management plane, while moving the API endpoint behind a VPN does not help once a key is stolen-an attacker can still act with full privileges from an approved location.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is it important to replace shared keys with individual administrator identities in cloud environments?
Open an interactive chat with Bash
What are IAM and RBAC, and how do they help improve cloud security?
Open an interactive chat with Bash
What is the principle of least privilege, and why is it critical in cloud security?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .