Courseiva

SSCP Systems and Application Security Practice Question

A cloud operations team is hardening the management plane of its Infrastructure as a Service (IaaS) environment. The team wants to reduce the risk of unauthorized administrative access to the cloud console and APIs. Which TWO of the following controls best address this objective? (Choose two.)

⚠ Common exam trap

The trap here is treating any cloud hardening action as relevant to management-plane access, when controls like versioning or CDN configuration do not authenticate or authorize administrative identities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce multi-factor authentication for all privileged accounts

Protecting the cloud management plane requires strong authentication and tight authorization. Multi-factor authentication ensures that a compromised password alone cannot grant administrative access, while least-privilege IAM policies limit what any authenticated identity can do. Together they reduce the likelihood and impact of unauthorized administrative access. The other choices concern storage durability, database sizing, and content delivery, none of which govern who can reach the console or APIs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a content delivery network in front of public web endpoints

    Why it's wrong here

    A content delivery network caches and distributes web content to improve latency and absorb traffic, and it may offer some edge filtering. It does not control access to the cloud console or management APIs, so it does not reduce unauthorized administrative access. This control addresses application delivery, not management-plane authentication or authorization.

  • ✓

    Enforce multi-factor authentication for all privileged accounts

    Why this is correct

    Multi-factor authentication requires a second factor beyond a password, so a stolen or guessed credential alone cannot grant console or API access. Applying it to privileged accounts directly reduces the risk of unauthorized administrative access, which is the stated objective. This is a foundational control for protecting the management plane of any IaaS environment.

  • ✓

    Apply least-privilege identity and access management policies to administrative roles

    Why this is correct

    Least-privilege IAM policies grant administrators only the permissions their duties require, shrinking the blast radius if an account is compromised and preventing unnecessary escalation paths. This directly limits unauthorized administrative access to the management plane. Combined with strong authentication, it forms a core defense for cloud administrative interfaces.

  • ✗

    Enable object storage versioning on application data buckets

    Why it's wrong here

    Object storage versioning preserves prior versions of objects so data can be recovered after accidental deletion or overwrite. It protects data integrity and availability but does not govern who can reach the cloud console or APIs. Since the objective concerns administrative access control, versioning is unrelated to reducing unauthorized management-plane entry.

  • ✗

    Increase the size of the managed database instance class

    Why it's wrong here

    Resizing a managed database instance affects performance and capacity, not access control. It neither authenticates administrators nor restricts which identities can invoke management APIs. Because the objective is reducing unauthorized administrative access, changing compute resources for a database has no bearing on the risk being addressed.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.