Courseiva

SSCP Systems and Application Security Practice Question

A cloud security architect is designing a solution to protect workloads running in a public cloud. Which THREE of the following are key security controls that should be implemented?

⚠ Common exam trap

The trap is that some options sound plausible but are either not security controls (A) or are insecure practices (C). Candidates might also overlook that the question asks for THREE, and E is correct but easy to miss if they focus only on the first two.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a Cloud Security Posture Management (CSPM) tool

Option B is correct because a Cloud Security Posture Management (CSPM) tool continuously monitors the cloud environment for misconfigurations, compliance violations, and policy drift, which is a foundational control for protecting public cloud workloads. Option D is correct because a Cloud Workload Protection Platform (CWPP) secures the actual workloads (VMs, containers, serverless functions) at runtime, providing vulnerability scanning, threat detection, and workload-level hardening. Option E is correct because implementing IAM roles with least privilege limits each identity to only the permissions required for its function, reducing the blast radius of compromised credentials and enforcing zero-trust access control. Option A is not a key control because storing encryption keys in the same region as the data does not improve security and may actually reduce resilience; key management should follow a dedicated KMS/HSM strategy with appropriate separation and replication. Option C is not a key control because disabling multi-factor authentication for service accounts weakens security and violates best practices; MFA or strong credential management should be enforced, not removed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store encryption keys in the same cloud region as the data

    Why it's wrong here

    Storing keys in the same region as the data means a single regional compromise or outage exposes both ciphertext and keys, defeating separation of duties. It is tempting because co-location reduces latency and simplifies key management, and it would be acceptable only where residency rules forbid cross-region key storage.

  • ✓

    Deploy a Cloud Security Posture Management (CSPM) tool

    Why this is correct

    CSPM continuously assesses cloud configuration against benchmarks and compliance baselines, detecting misconfigured storage, network and logging settings. It satisfies the stem's design requirement by addressing the misconfiguration risk inherent to public cloud, where provider-managed infrastructure removes traditional perimeter controls.

  • ✗

    Disable multi-factor authentication for service accounts

    Why it's wrong here

    Disabling multi-factor authentication weakens authentication for service accounts, removing a core identity control rather than adding one. It is tempting because service accounts cannot interactively respond to MFA prompts, so teams disable it for automation convenience, but the correct approach is short-lived credentials or workload identity federation.

  • ✓

    Use a Cloud Workload Protection Platform (CWPP)

    Why this is correct

    CWPP provides runtime protection for workloads themselves, covering vulnerability assessment, behavioural monitoring and process-level threat detection across VMs, containers and serverless. This satisfies the stem's workload-protection requirement, complementing posture and identity controls rather than replacing them.

  • ✓

    Implement IAM roles with least privilege

    Why this is correct

    IAM roles with least privilege grant only the permissions each workload or identity requires, limiting blast radius if credentials are compromised. This satisfies the stem's cloud security control requirement, since identity is the primary enforcement boundary in public cloud environments.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.