ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your development team is designing an application that will retrieve records from a back-end database through a dedicated service account. To reduce the blast radius of a credential leak, which requirement should the security architect include in the access-provisioning document?
Use the identical service account and credentials in development, staging, and production for deployment consistency.
Configure the account password to never expire in order to prevent application downtime.
Restrict the account's permissions to only the specific tables and query types the application needs.
Add the account to the database's full administrator role so schema migrations will succeed without manual intervention.
Granting the service account only the minimum database permissions required to perform its queries follows the principle of least privilege, a core requirement for non-human accounts. If the credentials are stolen, an attacker is limited to the small set of permitted operations. Reusing the same credentials in multiple environments, giving the account full administrator rights, or disabling password expiration all widen the attack surface and violate accepted service-account security practices.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least privilege?
Open an interactive chat with Bash
Why should service account credentials differ across development, staging, and production environments?
Open an interactive chat with Bash
What is the risk of using service accounts with full administrator rights?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .