SSCP Systems and Application Security Practice Question
A cloud operations team is hardening the management plane of its Infrastructure as a Service (IaaS) environment. The team wants to reduce the risk of unauthorized administrative access to the cloud console and APIs. Which TWO of the following controls best address this objective? (Choose two.)
⚠ Common exam trap
The trap here is treating any cloud hardening action as relevant to management-plane access, when controls like versioning or CDN configuration do not authenticate or authorize administrative identities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce multi-factor authentication for all privileged accounts
Protecting the cloud management plane requires strong authentication and tight authorization. Multi-factor authentication ensures that a compromised password alone cannot grant administrative access, while least-privilege IAM policies limit what any authenticated identity can do. Together they reduce the likelihood and impact of unauthorized administrative access. The other choices concern storage durability, database sizing, and content delivery, none of which govern who can reach the console or APIs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a content delivery network in front of public web endpoints
Why it's wrong here
A content delivery network caches and distributes web content to improve latency and absorb traffic, and it may offer some edge filtering. It does not control access to the cloud console or management APIs, so it does not reduce unauthorized administrative access. This control addresses application delivery, not management-plane authentication or authorization.
- ✓
Enforce multi-factor authentication for all privileged accounts
Why this is correct
Multi-factor authentication requires a second factor beyond a password, so a stolen or guessed credential alone cannot grant console or API access. Applying it to privileged accounts directly reduces the risk of unauthorized administrative access, which is the stated objective. This is a foundational control for protecting the management plane of any IaaS environment.
- ✓
Apply least-privilege identity and access management policies to administrative roles
Why this is correct
Least-privilege IAM policies grant administrators only the permissions their duties require, shrinking the blast radius if an account is compromised and preventing unnecessary escalation paths. This directly limits unauthorized administrative access to the management plane. Combined with strong authentication, it forms a core defense for cloud administrative interfaces.
- ✗
Enable object storage versioning on application data buckets
Why it's wrong here
Object storage versioning preserves prior versions of objects so data can be recovered after accidental deletion or overwrite. It protects data integrity and availability but does not govern who can reach the cloud console or APIs. Since the objective concerns administrative access control, versioning is unrelated to reducing unauthorized management-plane entry.
- ✗
Increase the size of the managed database instance class
Why it's wrong here
Resizing a managed database instance affects performance and capacity, not access control. It neither authenticates administrators nor restricts which identities can invoke management APIs. Because the objective is reducing unauthorized administrative access, changing compute resources for a database has no bearing on the risk being addressed.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.