ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization runs a multi-tenant SaaS platform in a public cloud. The DevOps team built a CI/CD pipeline that automatically deploys containers to production. A recent incident showed that long-lived IAM user keys hard-coded in the pipeline were leaked, allowing attackers to spin up rogue instances. To reduce the blast radius while still enabling automated deployments, which control provides the MOST effective mitigation?
Restrict the IAM user keys to the DevOps group and rotate them every 90 days.
Encrypt the existing IAM user keys with the cloud KMS service and store the ciphertext in the pipeline configuration.
Move the IAM user keys into environment variables defined in the Dockerfile so they are not visible in the code repository.
Use a secrets-management service that issues short-lived, single-use deployment credentials to the pipeline at run time and revokes them after completion.
Using a dedicated secrets-management service that supplies short-lived, single-use credentials to the pipeline follows the DevSecOps principle of just-in-time, least-privilege access. Dynamic secrets are created only when the job starts, are narrowly scoped to the deployment task, and are revoked automatically after completion, so any leaked value quickly becomes useless. Merely encrypting or relocating long-lived keys still leaves them valid if exposed, and periodic rotation of static keys leaves a window of opportunity between rotations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are short-lived credentials and why are they important?
Open an interactive chat with Bash
What is a secrets-management service?
Open an interactive chat with Bash
How does just-in-time access improve security?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .