Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud operations team is hardening the management plane of a production VPC. The security architect wants to reduce the risk of credential compromise and lateral movement through management interfaces. Which TWO measures best address this goal? (Choose two.)

⚠ Common exam trap

The trap here is selecting detective controls such as logging or perimeter controls such as bastion hosts, when the goal calls for preventive controls that shorten credential life and limit privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce least privilege on management roles and require multi-factor authentication for privileged sessions

Reducing management plane risk centers on making credentials short-lived and limiting what they can do. Federated identity with temporary credentials removes static keys that can be stolen and reused, while least privilege plus multi-factor authentication constrains the impact of any single compromised session. Together these directly attack credential compromise and lateral movement, whereas logging is detective and password length and bastion placement are secondary hardening steps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enforce least privilege on management roles and require multi-factor authentication for privileged sessions

    Why this is correct

    Least privilege limits what a compromised management credential can do, and mandatory multi-factor authentication makes stolen passwords or tokens insufficient on their own. Together they constrain both the likelihood of credential compromise succeeding and the scope of damage if it does. This combination is a core control for protecting administrative interfaces in cloud environments.

  • ✗

    Enable verbose API logging and forward all management events to a central log repository

    Why it's wrong here

    Comprehensive logging is essential for detection, forensics, and compliance, but it is a detective control that records activity after it occurs. It does not prevent credential compromise or block lateral movement in real time. Logging complements preventive measures but cannot substitute for them when the goal is to reduce the risk itself.

  • ✗

    Place management interfaces behind a bastion host reachable only from a corporate IP range

    Why it's wrong here

    A bastion host with IP allowlisting reduces exposure but still concentrates privileged access on a single jump point that becomes a high-value target. If the bastion is compromised, the attacker inherits its network position and any cached credentials. This is a useful layer but does not by itself address credential lifetime or lateral movement as directly as federation does.

  • ✓

    Replace long-lived access keys with short-lived credentials issued through a federated identity provider

    Why this is correct

    Federated identity issues temporary credentials scoped to a role and session, so stolen credentials expire quickly and cannot be reused indefinitely. This directly reduces the blast radius of credential compromise and eliminates the sprawl of static access keys that are hard to rotate. It addresses the management plane risk by shrinking the window in which a leaked credential is useful.

  • ✗

    Increase the password complexity policy for all administrative accounts to twenty characters

    Why it's wrong here

    Stronger passwords raise the cost of brute-force and guessing attacks, but they do nothing against phishing, credential stuffing, or keys leaked through code repositories. Length alone does not address the short-lived credential and least-privilege principles that most effectively contain management plane compromise. It is a marginal improvement rather than a primary mitigation.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.