CCSP Cloud Platform and Infrastructure Security Practice Question
A DevOps team deploys workloads on a public cloud using infrastructure as code. A security review finds that a developer's pipeline credentials can both modify production network security groups and read secrets from the key management service. Which cloud infrastructure security principle is most directly violated?
⚠ Common exam trap
The trap here is reaching for a broad architectural principle like defense in depth when the finding is specifically about one identity holding conflicting privileges that defeat separation of duties.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties enforced through least-privilege IAM roles
The pipeline identity combines the power to weaken production network controls with the power to read protected secrets, so a single compromised credential can both disable defenses and steal data. Enforcing separation of duties through least-privilege IAM roles splits these capabilities across distinct identities, removing the toxic combination the review uncovered.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immutable infrastructure with version-controlled deployment artifacts
Why it's wrong here
Immutability addresses drift and rollback reliability by replacing rather than mutating instances. The scenario describes excessive privilege in a pipeline identity, which can occur regardless of whether infrastructure is mutable or immutable. Treating every deployment as a fresh artifact would not prevent the credential from reading secrets or rewriting firewall rules.
- ✓
Separation of duties enforced through least-privilege IAM roles
Why this is correct
Separation of duties requires that no single identity hold both the ability to change protective controls and the ability to access the assets those controls protect. A pipeline credential that can alter production security groups and read secrets can silently disable defenses before exfiltrating data, which is exactly the toxic combination this principle is designed to prevent.
- ✗
Data residency controls restricting where tenant data is stored
Why it's wrong here
Data residency governs the geographic placement and legal jurisdiction of stored data. Nothing in the finding indicates that data crossed a border or violated a residency commitment; the problem is excessive authorization. Applying residency constraints would leave the toxic privilege combination fully intact.
- ✗
Defense in depth using layered network and host controls
Why it's wrong here
Defense in depth is about overlapping controls so that failure of one layer does not cause total compromise. The finding here is about a single identity wielding two conflicting privileges, not about missing layers of protection. Adding more controls would not fix the underlying privilege concentration, so this principle is not the one most directly violated.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.