ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a security design review of a cloud-native application, you must document requirements for how microservices will obtain database credentials for their service accounts. Which approach MOST directly satisfies secure credential storage and rotation expectations for service accounts under the CSSLP data access provisioning objective?
Store the service account credentials in a version-controlled, GPG-encrypted YAML file and replace the encryption key once a year.
Embed the database password in an environment variable for each microservice and encrypt the container image at rest.
Leverage an enterprise secrets vault that injects short-lived, automatically rotated database credentials into each container at start-up.
Use a service account with a non-expiring password and rely on network security groups to restrict database access.
Using a centralized secrets-management service that issues short-lived, dynamically generated credentials fulfils two key requirements: the secret is never stored with the application (secure storage) and it is transparently replaced at a set interval or on demand (automated rotation). All other options leave long-lived passwords in code, configuration, or the account itself, making secrets harder to protect and rotate and increasing the window of exposure if they are compromised.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a secrets vault in the context of secure software development?
Open an interactive chat with Bash
Why is automated credential rotation important for security?
Open an interactive chat with Bash
How does injecting credentials at container start-up enhance security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .