ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an architecture review for a multi-tenant SaaS platform, the team discusses how to reduce the exposure that one tenant's compromise could present to others. Which design choice most strongly applies the security principle of least common mechanism?
Keep all tenants' session state in a single in-memory cache protected by access-control lists.
Write logs from all microservices into one centrally mounted file that every service can read and append to.
Deploy a separate API gateway for every tenant, each running its own authentication and authorization plug-ins.
Run the microservices for all tenants in the same container network namespace to simplify east-west traffic routing.
Least common mechanism advises minimizing any component or resource that is shared by multiple users or processes, because a flaw or misuse in that common element can become a conduit for compromise across boundaries. Providing a dedicated API gateway for each tenant ensures that authentication, authorization, and request handling are isolated; no single gateway failure can leak data or permissions to another tenant. The other options consolidate critical functions-shared log files, common session caches, or a single container namespace-creating shared attack surfaces that violate the principle.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least common mechanism?
Open an interactive chat with Bash
Why is deploying separate API gateways beneficial in multi-tenant SaaS platforms?
Open an interactive chat with Bash
What are the risks of a shared session cache in multi-tenant environments?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .