SSCP Systems and Application Security Practice Question
A cloud security architect is designing a solution to protect workloads running in a public cloud. Which THREE of the following are key security controls that should be implemented?
⚠ Common exam trap
The trap is that some options sound plausible but are either not security controls (A) or are insecure practices (C). Candidates might also overlook that the question asks for THREE, and E is correct but easy to miss if they focus only on the first two.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a Cloud Security Posture Management (CSPM) tool
Option B is correct because a Cloud Security Posture Management (CSPM) tool continuously monitors the cloud environment for misconfigurations, compliance violations, and policy drift, which is a foundational control for protecting public cloud workloads. Option D is correct because a Cloud Workload Protection Platform (CWPP) secures the actual workloads (VMs, containers, serverless functions) at runtime, providing vulnerability scanning, threat detection, and workload-level hardening. Option E is correct because implementing IAM roles with least privilege limits each identity to only the permissions required for its function, reducing the blast radius of compromised credentials and enforcing zero-trust access control. Option A is not a key control because storing encryption keys in the same region as the data does not improve security and may actually reduce resilience; key management should follow a dedicated KMS/HSM strategy with appropriate separation and replication. Option C is not a key control because disabling multi-factor authentication for service accounts weakens security and violates best practices; MFA or strong credential management should be enforced, not removed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store encryption keys in the same cloud region as the data
Why it's wrong here
Storing keys in the same region as the data means a single regional compromise or outage exposes both ciphertext and keys, defeating separation of duties. It is tempting because co-location reduces latency and simplifies key management, and it would be acceptable only where residency rules forbid cross-region key storage.
- ✓
Deploy a Cloud Security Posture Management (CSPM) tool
Why this is correct
CSPM continuously assesses cloud configuration against benchmarks and compliance baselines, detecting misconfigured storage, network and logging settings. It satisfies the stem's design requirement by addressing the misconfiguration risk inherent to public cloud, where provider-managed infrastructure removes traditional perimeter controls.
- ✗
Disable multi-factor authentication for service accounts
Why it's wrong here
Disabling multi-factor authentication weakens authentication for service accounts, removing a core identity control rather than adding one. It is tempting because service accounts cannot interactively respond to MFA prompts, so teams disable it for automation convenience, but the correct approach is short-lived credentials or workload identity federation.
- ✓
Use a Cloud Workload Protection Platform (CWPP)
Why this is correct
CWPP provides runtime protection for workloads themselves, covering vulnerability assessment, behavioural monitoring and process-level threat detection across VMs, containers and serverless. This satisfies the stem's workload-protection requirement, complementing posture and identity controls rather than replacing them.
- ✓
Implement IAM roles with least privilege
Why this is correct
IAM roles with least privilege grant only the permissions each workload or identity requires, limiting blast radius if credentials are compromised. This satisfies the stem's cloud security control requirement, since identity is the primary enforcement boundary in public cloud environments.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.