hardMultiple Choice
CCSP Practice Question: A cloud security engineer is responsible for a…
A cloud security engineer is responsible for a SaaS application hosted on a public cloud provider. The application uses a relational database to store customer data. The security team recently conducted a vulnerability assessment and discovered that the database can be accessed over the internet without any network restrictions. Additionally, the database admin user has the same password as the root account, and the password has not been changed in 18 months. The company is subject to GDPR and PCI DSS compliance requirements. The engineer needs to remediate these issues immediately. Which of the following actions should be taken FIRST?
⚠ Common exam trap
The trap is prioritizing password change or encryption over network restriction. Candidates might think that changing the password is the first step, but the exposure to the internet is the most critical vulnerability that must be addressed immediately to prevent unauthorized access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the database security group to allow traffic only from the application server's IP address range.
The most critical immediate action is to restrict network access to the database, as it is currently exposed to the internet without restrictions. This is the highest risk because it allows anyone to attempt to connect, potentially leading to unauthorized access. Configuring the security group to allow traffic only from the application server's IP range is the first step to remediate the exposure. While changing the password is also important, the network exposure is the most severe and immediate threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the database admin password to a complex new password immediately.
Why it's wrong here
Changing the admin password alone leaves the database reachable from the internet, so the exposed attack surface remains. It is tempting because credential hygiene is a clear finding, and would be correct after network access is restricted to trusted sources.
- ✗
Upgrade the database to the latest version with all security patches applied.
Why it's wrong here
Patching addresses software vulnerabilities, not the internet exposure or shared, stale credentials flagged here. It is tempting because patch management is a core hardening task, and it would be correct if the assessment had found unpatched CVEs on an otherwise restricted database.
- ✓
Configure the database security group to allow traffic only from the application server's IP address range.
Why this is correct
Internet-exposed database access is the most severe issue, so restricting the security group to the application server's IP range immediately removes public reachability. This satisfies GDPR and PCI DSS network segmentation requirements before addressing the shared, stale admin password.
- ✗
Enable encryption at rest for the database to protect the data if it is stolen.
Why it's wrong here
Encryption at rest protects stored data but leaves the internet-exposed database and shared, stale credentials exploitable, so it does not address the immediate attack path. It is tempting as a compliance control, and would be correct once network and identity exposure are contained.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.