ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While designing a production Kubernetes cluster for a payment-processing platform, you must give operations staff access to the kube-api server and occasional SSH access to worker nodes. Policy states that management traffic must be isolated from customer workload traffic and continuously monitored. Which architectural choice BEST satisfies these requirements while honoring the principle of least privilege?
Keep management ports on the production network but restrict them with host-based firewall rules to specific administrator IP addresses.
Expose the Kubernetes dashboard on the existing public load balancer over TLS with client certificates for administrators.
Tunnel all management commands through the application's public REST API using HTTPS to avoid opening additional ports.
Place all management interfaces on a dedicated, isolated subnet reachable only through a hardened bastion host protected by multi-factor authentication.
Placing all management interfaces on a dedicated subnet that is reachable only through a hardened bastion (jump) host enforces true out-of-band access. The bastion restricts entry to a single, tightly controlled point, where multi-factor authentication and monitoring can be applied. Exposing the dashboard on the public load balancer still mixes management and user traffic, increasing attack surface. Relying solely on host-based firewalls keeps management ports on the production network and does not ensure traffic is monitored separately. Tunneling management commands through the public REST API violates separation of duties and unnecessarily enlarges the application attack surface.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least privilege?
Open an interactive chat with Bash
What is a bastion host and how is it hardened?
Open an interactive chat with Bash
Why is out-of-band access important for management interfaces?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .