Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityEasy
A security architect is designing a cloud-native application that will process sensitive customer data. The application will leverage microservices deployed in a public cloud environment. Which security principle is most critical to ensure that a breach in one microservice does not compromise the entire application's data?
- AStrong multi-factor authentication for users
- BAutomated incident response
- CCentralized logging and monitoring
- DLeast privilege and segmentation
Show answer & explanationAnswer & explanation
Correct answer: D. Least privilege and segmentation
Least privilege ensures that each microservice only has the permissions it needs, and segmentation isolates them, preventing lateral movement in case of a compromise. This directly addresses the scenario of limiting a breach's impact.
Why the other options are wrong
- A. MFA protects user access, but not internal microservice-to-microservice communication and data access post-authentication.
- B. Automated incident response is reactive; the question asks about preventing widespread compromise.
- C. While important for detection, centralized logging doesn't prevent a breach from spreading.
Least Privilege
A security principle where every user, process, and program is granted only the minimum permissions necessary to perform its function.
- Reduces the attack surface.
- Limits the 'blast radius' of a security breach.
- Fundamental for zero-trust architectures.
Memory trick: Cloud Security: Protect Data, Isolate Threats, Respond Fast, Trust No One.