Courseiva
mediumMultiple Select

CCSP Practice Question: A cloud application is deployed on Kubernetes and…

A cloud application is deployed on Kubernetes and uses a cloud identity and access management (IAM) role for service accounts. Which TWO practices should be implemented to ensure least privilege?

⚠ Common exam trap

The trap is that candidates may think 'encrypting' or 'using a role' is enough, but least privilege specifically requires both minimal permissions and resource-level scoping — broad roles are a common misconfiguration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant only the specific permissions required for the application

Option A is correct because least privilege requires granting only the specific permissions the application actually needs, avoiding broad or wildcard permissions that expand the attack surface. Option D is correct because scoping the IAM role to specific resource identifiers (e.g., a particular bucket or secret) ensures the role can only act on the resources it legitimately requires, further tightening access. Option B is wrong because hardcoding credentials in application code exposes secrets and violates secure credential management, typically handled via workload identity or mounted tokens. Option C is wrong because granting full IAM permissions such as 'iam:*' is the opposite of least privilege and grants excessive access. Option E is wrong because sharing a single role across all services in the cluster removes per-service isolation and grants each service more permissions than it needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Grant only the specific permissions required for the application

    Why this is correct

    Granting only the permissions the application actually calls enforces least privilege at the policy level, so the service account cannot perform unrelated actions. This directly satisfies the requirement by eliminating wildcard or broad permissions that exceed the application's operational needs.

  • ✗

    Hardcode the role's credentials in the application code

    Why it's wrong here

    Embedding credentials in source code exposes them to anyone with repository access and prevents rotation, defeating least privilege. It is tempting because hardcoding removes runtime credential lookups, but the correct practise is retrieving short-lived credentials from the cloud IAM role via workload identity.

  • ✗

    Grant the role the full IAM permissions (e.g., 'iam:*' equivalent)

    Why it's wrong here

    Granting iam:* violates least privilege outright, since the service account could create users, delete roles or alter policies far beyond its workload. It is tempting because wildcard grants remove permission-denied errors during development, and would suit a throwaway sandbox, but production Kubernetes workloads need narrowly scoped actions on named resources.

  • ✓

    Restrict the role to specific resources using resource identifiers

    Why this is correct

    Scoping the IAM role to explicit resource identifiers, such as ARNs, prevents the service account from acting on unrelated buckets, queues or tables. This satisfies least privilege by bounding permissions to named resources rather than granting account-wide access.

  • ✗

    Use a single role for all services in the cluster

    Why it's wrong here

    One shared role grants every service the union of all permissions, so each pod gains far more than its task requires. It is tempting because a single role simplifies administration, but least privilege demands per-service accounts with narrowly scoped permissions.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.