ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During an internal audit of your company's new SaaS-based CRM solution, you discover that the same DevOps engineers who deploy application code also generate and rotate the tenant data-encryption keys through the cloud provider's KMS. From an internal information security controls system perspective, which recommendation would most effectively reduce the risk of unauthorized key modification?
Require multi-factor authentication for administrators accessing the CRM application dashboard.
Enable automatic rotation of all encryption keys every 30 days using the provider's KMS.
Store the encryption keys in the same source-code repository but restrict push access to DevOps leads.
Transfer key-management duties to an independent security operations team to enforce segregation of duties.
A well-designed internal information security controls system relies on segregation of duties to ensure that no single individual can both introduce and authorize changes that might compromise security. Moving key-management responsibilities to an independent security or key-management team breaks the potential conflict of interest created when DevOps staff both deploy code and control encryption keys. The other options improve security in limited ways-such as tightening repository access, shortening rotation intervals, or adding MFA for administrators-but none address the fundamental control weakness that the same role both develops code and controls the cryptographic keys that protect production data.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of segregation of duties in information security?
Open an interactive chat with Bash
What is a Key Management System (KMS), and why is it important in cloud environments?
Open an interactive chat with Bash
How does automatic key rotation improve security, and what are its limitations?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .