Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A DevOps team deploys workloads on a public cloud using infrastructure as code. A security review finds that a developer's pipeline credentials can both modify production network security groups and read secrets from the key management service. Which cloud infrastructure security principle is most directly violated?

⚠ Common exam trap

The trap here is reaching for a broad architectural principle like defense in depth when the finding is specifically about one identity holding conflicting privileges that defeat separation of duties.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Separation of duties enforced through least-privilege IAM roles

The pipeline identity combines the power to weaken production network controls with the power to read protected secrets, so a single compromised credential can both disable defenses and steal data. Enforcing separation of duties through least-privilege IAM roles splits these capabilities across distinct identities, removing the toxic combination the review uncovered.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immutable infrastructure with version-controlled deployment artifacts

    Why it's wrong here

    Immutability addresses drift and rollback reliability by replacing rather than mutating instances. The scenario describes excessive privilege in a pipeline identity, which can occur regardless of whether infrastructure is mutable or immutable. Treating every deployment as a fresh artifact would not prevent the credential from reading secrets or rewriting firewall rules.

  • ✓

    Separation of duties enforced through least-privilege IAM roles

    Why this is correct

    Separation of duties requires that no single identity hold both the ability to change protective controls and the ability to access the assets those controls protect. A pipeline credential that can alter production security groups and read secrets can silently disable defenses before exfiltrating data, which is exactly the toxic combination this principle is designed to prevent.

  • ✗

    Data residency controls restricting where tenant data is stored

    Why it's wrong here

    Data residency governs the geographic placement and legal jurisdiction of stored data. Nothing in the finding indicates that data crossed a border or violated a residency commitment; the problem is excessive authorization. Applying residency constraints would leave the toxic privilege combination fully intact.

  • ✗

    Defense in depth using layered network and host controls

    Why it's wrong here

    Defense in depth is about overlapping controls so that failure of one layer does not cause total compromise. The finding here is about a single identity wielding two conflicting privileges, not about missing layers of protection. Adding more controls would not fix the underlying privilege concentration, so this principle is not the one most directly violated.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.