CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud security team is designing the management plane for a regulated workload on a public IaaS platform. They must ensure that administrative access to the cloud console and APIs is strongly controlled. Which TWO measures best satisfy this requirement? (Choose two.)
⚠ Common exam trap
The trap here is selecting logging or network acceleration measures that sound like security controls but only observe or optimize traffic rather than preventing unauthorized administrative access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict administrative API calls to approved source networks using provider policy conditions
Protecting the management plane requires both strong authentication and contextual authorization. Phishing-resistant multifactor authentication stops credential theft, while policy conditions that restrict administrative API calls to approved source networks ensure that even a stolen credential cannot be replayed from an untrusted location. Together they address identity and context, which are the two levers tenants control over the provider's management plane.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restrict administrative API calls to approved source networks using provider policy conditions
Why this is correct
Many cloud providers let administrators attach conditions to IAM policies that evaluate the source network of an API call. Requiring administrative actions to originate from a known corporate range or a bastion network means a stolen credential used from an attacker's location is rejected outright, adding a strong contextual control independent of the credential itself.
- ✗
Issue long-lived access keys to automation accounts to simplify pipeline authentication
Why it's wrong here
Long-lived static keys are a leading cause of cloud breaches because they cannot be tied to a short session, are easily copied into code repositories, and often lack rotation. This measure weakens management plane security rather than strengthening it, and the recommended pattern is short-lived credentials issued through federation or workload identity.
- ✗
Deploy a content delivery network in front of the provider's management console endpoints
Why it's wrong here
A content delivery network caches and accelerates content for end users; it cannot be placed in front of provider-owned console endpoints and does nothing to authenticate or authorize administrative callers. This measure misunderstands the control boundary, since the management plane is operated by the provider, not the tenant's edge infrastructure.
- ✗
Enable verbose object storage access logging for all buckets in the account
Why it's wrong here
Access logging records data-plane operations against storage objects and supports forensics and compliance evidence. It does not restrict who can call management APIs or how they authenticate, so it is a detective control rather than a preventive one. Verbose logging also increases cost and noise without reducing the management plane's exposure.
- ✓
Enforce phishing-resistant multifactor authentication for all administrative identities
Why this is correct
The management plane is the highest-value target because it can reconfigure or delete any resource. Requiring phishing-resistant factors such as hardware security keys or platform-bound passkeys prevents credential replay and adversary-in-the-middle phishing, which are the dominant ways administrative sessions are stolen. This directly hardens the identities that can wield control-plane power.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.