ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization manages cloud resources with Terraform files stored in a Git repository that requires pull-request reviews before merge. From a security standpoint, what is the primary advantage of this Infrastructure as Code practice over making one-off changes directly in the cloud provider's web console?
All cloud data is automatically encrypted at rest without needing additional configuration steps.
It eliminates the need for formal change-management approval, allowing faster deployments without peer review.
The approach inherently protects resources from denial-of-service attacks by throttling API requests.
Each infrastructure change is tracked in version control, creating an auditable history and enabling safe rollback to trusted states.
Storing Infrastructure as Code (IaC) definitions such as Terraform in a version-controlled repository means every change is treated like a code commit. The history of modifications is automatically recorded, peer review can be enforced through pull-request workflows, and previous known-good states can be restored if an error or malicious change is discovered. These capabilities give security teams a clear audit trail and help prevent configuration drift. While IaC can facilitate encryption settings or API rate controls, those specific protections still require explicit configuration. Similarly, formal code reviews supplement-rather than replace-organizational change-management approval processes.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Infrastructure as Code (IaC)?
Open an interactive chat with Bash
Why is version control important in managing Terraform files?
Open an interactive chat with Bash
What is configuration drift, and how does IaC help prevent it?
Open an interactive chat with Bash
What is Infrastructure as Code (IaC)?
Open an interactive chat with Bash
Why is version control important for IaC security?
Open an interactive chat with Bash
What is 'configuration drift' in cloud infrastructure?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .