ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization is moving an internal HR application to virtual machines hosted in a public IaaS environment. Security policy requires that employees continue to authenticate with their on-premises Active Directory credentials and that only the HR support group may administer the cloud resources used by the application. Which identity and access control solution best meets these requirements while honoring least-privilege principles?

  • Permit anonymous access to the cloud resource endpoints and rely solely on application-level authentication.

  • Configure SAML 2.0 federation between Active Directory Federation Services and the cloud provider, mapping AD groups to fine-grained IAM roles.

  • Embed shared root-level SSH keys into the VM images and distribute the key pair to the HR team.

  • Create individual IAM users in the cloud provider and enforce complex password rotation policies.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot