Courseiva

CCSP Cloud Application Security Practice Question

A cloud provider's API is used by an application to retrieve secrets from a managed secrets store. The security team wants to ensure that if a secret is compromised, its use is limited to a short window and that all access is attributable to a specific workload identity. Which combination best meets these requirements?

⚠ Common exam trap

The trap here is assuming that encrypting a static secret or adding approval steps limits its use after compromise, when only short-lived, identity-bound credentials reduce the exposure window.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the secrets store's dynamic secrets feature to issue short-lived credentials tied to the workload's authenticated identity, with audit logging of each issuance.

Dynamic secrets issued to an authenticated workload identity provide short-lived credentials and per-issuance audit trails. If a credential leaks, its TTL limits the damage, and logs attribute each issuance to a specific workload. Static secrets in environment variables, encrypted secrets with dual approval, and secrets embedded in images do not provide both short-lived use and workload-level attribution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use the secrets store's dynamic secrets feature to issue short-lived credentials tied to the workload's authenticated identity, with audit logging of each issuance.

    Why this is correct

    Dynamic secrets generate credentials on demand with a short time-to-live and bind them to the requesting workload's authenticated identity. Each issuance is logged, providing attribution. If compromised, the credential expires quickly, limiting the window of use. This directly satisfies both the short-lived use and attribution requirements.

  • ✗

    Store the secret in an environment variable on the compute instance and rotate it every 90 days using a scheduled job.

    Why it's wrong here

    Environment variables can leak through process listings, crash dumps, and logs, and a 90-day rotation leaves a long exposure window if compromised. It also does not provide per-workload attribution because the secret is a static credential. This fails both the short-lived use and workload identity requirements.

  • ✗

    Encrypt the secret with a customer-managed key and require two administrators to approve each retrieval.

    Why it's wrong here

    Encryption with a customer-managed key protects the secret at rest, and dual approval adds a control, but the retrieved secret remains a static credential with no inherent expiry. It does not limit the use window after compromise, and attribution depends on the approval workflow rather than the workload identity, so it does not meet the requirements.

  • ✗

    Embed the secret in the container image and rely on image signing to ensure only trusted images run.

    Why it's wrong here

    Embedding secrets in images exposes them to anyone who can pull the image and creates a long-lived credential that is hard to rotate. Image signing verifies provenance but not secret handling. This approach fails both the short-lived use and workload attribution requirements and is a well-known anti-pattern.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.