Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud security administrator is responsible for managing access to a cloud management console. The organization wants to enforce multi-factor authentication (MFA) for all human users and ensure that programmatic access uses short-lived credentials instead of long-term access keys. Which approach BEST aligns with these requirements?

⚠ Common exam trap

The trap here is thinking that rotating long-term access keys or enabling MFA only for the root account satisfies the requirement, when true compliance requires federation with MFA and temporary credentials for programmatic access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an identity provider with SAML 2.0 federation for console access with MFA enforced, and use IAM roles with temporary credentials for programmatic access via AWS STS.

Enforcing MFA for human users is best achieved through federation with an identity provider that applies MFA, such as SAML 2.0, which issues temporary console sessions. For programmatic access, assuming IAM roles via AWS STS provides temporary credentials that rotate automatically, eliminating long-term access keys. Together these practices enforce MFA and short-lived credentials, aligning with cloud security best practices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use an identity provider with SAML 2.0 federation for console access with MFA enforced, and use IAM roles with temporary credentials for programmatic access via AWS STS.

    Why this is correct

    SAML 2.0 federation with an identity provider enforces MFA at the identity provider and issues temporary console sessions. For programmatic access, assuming IAM roles via AWS STS provides short-lived credentials that expire automatically. This combination meets both requirements without long-term keys.

  • ✗

    Create a single shared IAM user for all administrators with MFA enabled and distribute the access keys securely to the team.

    Why it's wrong here

    Shared credentials eliminate individual accountability and make it impossible to audit who performed an action. Distributing access keys also creates long-term credentials. This violates least privilege and the requirement for short-lived programmatic credentials, and it does not scale securely.

  • ✗

    Create IAM users with long-term access keys and attach an IAM policy that requires MFA for console access only.

    Why it's wrong here

    Long-term access keys do not expire and are a common source of credential leakage. Requiring MFA only for console access leaves programmatic access unprotected and does not enforce short-lived credentials. This approach fails the requirement to use short-lived credentials for programmatic access.

  • ✗

    Store IAM user access keys in AWS Secrets Manager and rotate them every 90 days, while enabling MFA for the root account only.

    Why it's wrong here

    Storing and rotating long-term access keys still creates long-lived credentials that can be leaked. Enabling MFA only for the root account does not protect other human users. This does not enforce MFA for all users or eliminate long-term programmatic credentials.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.