CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud operations team is hardening the management plane of a production VPC. The security architect wants to reduce the risk of credential compromise and lateral movement through management interfaces. Which TWO measures best address this goal? (Choose two.)
⚠ Common exam trap
The trap here is selecting detective controls such as logging or perimeter controls such as bastion hosts, when the goal calls for preventive controls that shorten credential life and limit privilege.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce least privilege on management roles and require multi-factor authentication for privileged sessions
Reducing management plane risk centers on making credentials short-lived and limiting what they can do. Federated identity with temporary credentials removes static keys that can be stolen and reused, while least privilege plus multi-factor authentication constrains the impact of any single compromised session. Together these directly attack credential compromise and lateral movement, whereas logging is detective and password length and bastion placement are secondary hardening steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enforce least privilege on management roles and require multi-factor authentication for privileged sessions
Why this is correct
Least privilege limits what a compromised management credential can do, and mandatory multi-factor authentication makes stolen passwords or tokens insufficient on their own. Together they constrain both the likelihood of credential compromise succeeding and the scope of damage if it does. This combination is a core control for protecting administrative interfaces in cloud environments.
- ✗
Enable verbose API logging and forward all management events to a central log repository
Why it's wrong here
Comprehensive logging is essential for detection, forensics, and compliance, but it is a detective control that records activity after it occurs. It does not prevent credential compromise or block lateral movement in real time. Logging complements preventive measures but cannot substitute for them when the goal is to reduce the risk itself.
- ✗
Place management interfaces behind a bastion host reachable only from a corporate IP range
Why it's wrong here
A bastion host with IP allowlisting reduces exposure but still concentrates privileged access on a single jump point that becomes a high-value target. If the bastion is compromised, the attacker inherits its network position and any cached credentials. This is a useful layer but does not by itself address credential lifetime or lateral movement as directly as federation does.
- ✓
Replace long-lived access keys with short-lived credentials issued through a federated identity provider
Why this is correct
Federated identity issues temporary credentials scoped to a role and session, so stolen credentials expire quickly and cannot be reused indefinitely. This directly reduces the blast radius of credential compromise and eliminates the sprawl of static access keys that are hard to rotate. It addresses the management plane risk by shrinking the window in which a leaked credential is useful.
- ✗
Increase the password complexity policy for all administrative accounts to twenty characters
Why it's wrong here
Stronger passwords raise the cost of brute-force and guessing attacks, but they do nothing against phishing, credential stuffing, or keys leaked through code repositories. Length alone does not address the short-lived credential and least-privilege principles that most effectively contain management plane compromise. It is a marginal improvement rather than a primary mitigation.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.