ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A DevSecOps team must enable employees to access five internal microservices. To apply the economy of mechanism principle while also reducing password fatigue for users, which authentication approach is MOST appropriate?
Require users to maintain separate usernames and passwords for every microservice but enforce identical password complexity rules.
Integrate all services with a centralized SAML/OIDC-based single sign-on service provided by a well-vetted identity provider.
Store each user's credentials in an encrypted environment file on every host and have services read the file locally at startup.
Develop a distinct custom authentication library for each microservice, using different encryption algorithms to diversify defenses.
Economy of mechanism favors the simplest security design that still meets requirements. Reusing a single, battle-tested identity provider to supply SAML or OIDC tokens lets each microservice rely on the same straightforward mechanism, avoids duplicating complex authentication code, and gives users one credential set (SSO). Writing separate custom modules, storing credentials in local files, or forcing unique logins for every service all add unnecessary components or credentials, increasing attack surface and violating the simplicity goal.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SAML and OIDC?
Open an interactive chat with Bash
How does Single Sign-On (SSO) reduce password fatigue?
Open an interactive chat with Bash
Why is the economy of mechanism principle important in security design?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .