ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a security assessment of a microservices payment platform, you find the order-processing service connects to a PostgreSQL instance using a role that has SELECT, INSERT, UPDATE, and DELETE on every table. The service only needs to read order-status data. Which remediation best enforces least privilege?
Force the service to rotate its database credentials every 30 days while keeping current role privileges unchanged.
Deploy a web application firewall in front of the service to filter malicious input before it reaches the database.
Move the database to an isolated virtual private cloud (VPC) and maintain the existing role permissions.
Create a new database role for the service restricted to SELECT privileges on the required order-status tables only.
Granting the service a dedicated database role that can only perform SELECT operations on the specific tables it truly needs limits both the objects it can access and the actions it can perform. This directly enforces least privilege by preventing any write, modify, or delete actions. Network segmentation, credential rotation, and a web application firewall each strengthen security in other ways but do not reduce the service's database permissions and therefore do not correct the least-privilege violation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is the principle of least privilege important in database security?
Open an interactive chat with Bash
What are database roles and how do they enforce security?
Open an interactive chat with Bash
What is the difference between isolating databases on a VPC and enforcing least privilege through roles?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .