mediumMultiple Select
CCSP Practice Question: A cloud application is deployed on Kubernetes and…
A cloud application is deployed on Kubernetes and uses a cloud identity and access management (IAM) role for service accounts. Which TWO practices should be implemented to ensure least privilege?
⚠ Common exam trap
The trap is that candidates may think 'encrypting' or 'using a role' is enough, but least privilege specifically requires both minimal permissions and resource-level scoping — broad roles are a common misconfiguration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant only the specific permissions required for the application
Option A is correct because least privilege requires granting only the specific permissions the application actually needs, avoiding broad or wildcard permissions that expand the attack surface. Option D is correct because scoping the IAM role to specific resource identifiers (e.g., a particular bucket or secret) ensures the role can only act on the resources it legitimately requires, further tightening access. Option B is wrong because hardcoding credentials in application code exposes secrets and violates secure credential management, typically handled via workload identity or mounted tokens. Option C is wrong because granting full IAM permissions such as 'iam:*' is the opposite of least privilege and grants excessive access. Option E is wrong because sharing a single role across all services in the cluster removes per-service isolation and grants each service more permissions than it needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Grant only the specific permissions required for the application
Why this is correct
Granting only the permissions the application actually calls enforces least privilege at the policy level, so the service account cannot perform unrelated actions. This directly satisfies the requirement by eliminating wildcard or broad permissions that exceed the application's operational needs.
- ✗
Hardcode the role's credentials in the application code
Why it's wrong here
Embedding credentials in source code exposes them to anyone with repository access and prevents rotation, defeating least privilege. It is tempting because hardcoding removes runtime credential lookups, but the correct practise is retrieving short-lived credentials from the cloud IAM role via workload identity.
- ✗
Grant the role the full IAM permissions (e.g., 'iam:*' equivalent)
Why it's wrong here
Granting iam:* violates least privilege outright, since the service account could create users, delete roles or alter policies far beyond its workload. It is tempting because wildcard grants remove permission-denied errors during development, and would suit a throwaway sandbox, but production Kubernetes workloads need narrowly scoped actions on named resources.
- ✓
Restrict the role to specific resources using resource identifiers
Why this is correct
Scoping the IAM role to explicit resource identifiers, such as ARNs, prevents the service account from acting on unrelated buckets, queues or tables. This satisfies least privilege by bounding permissions to named resources rather than granting account-wide access.
- ✗
Use a single role for all services in the cluster
Why it's wrong here
One shared role grants every service the union of all permissions, so each pod gains far more than its task requires. It is tempting because a single role simplifies administration, but least privilege demands per-service accounts with narrowly scoped permissions.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.