ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A financial company exposes an internal payments microservice to a partner bank through an API-management middleware hosted in its DMZ. The partner must act on behalf of individual end users while the payments service should never accept broad partner credentials. Which design best enforces least privilege and provides a verifiable trust path across this third-party connection?
The partner authenticates once daily with a long-lived mutual-TLS session, and the middleware forwards all subsequent requests under that session.
The middleware uses a stored shared database account with full DML rights that the partner invokes through predefined procedures.
The partner places a base64-encoded user ID in a custom HTTP header, which the microservice accepts if the request originates from the middleware's IP address.
The middleware exchanges the partner's JWT for a short-lived, scope-limited OAuth2 access token issued per user request before forwarding it to the microservice.
Translating the partner's authentication token into a short-lived, narrowly scoped OAuth2 access token means the middleware presents the microservice with the minimum rights needed for the specific user request. Each call can be audited to an individual identity, and the token's lifetime and scopes limit abuse. Relying solely on a mutual TLS channel, shared database credentials, or trusting a custom header tied only to source IP extends excessive or unauthenticated privileges and defeats traceability, violating least-privilege principles.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a JWT and why is it used in secure communication?
Open an interactive chat with Bash
What is OAuth2 and how does it enforce least privilege in API design?
Open an interactive chat with Bash
Why is the DMZ important in hosting middleware for third-party connections?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .