Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityEasy

A security architect is designing a cloud-native application that will process sensitive customer data. The application will leverage microservices deployed in a public cloud environment. Which security principle is most critical to ensure that a breach in one microservice does not compromise the entire application's data?

  1. AStrong multi-factor authentication for users
  2. BAutomated incident response
  3. CCentralized logging and monitoring
  4. DLeast privilege and segmentation
Show answer & explanation

Correct answer: D. Least privilege and segmentation

Least privilege ensures that each microservice only has the permissions it needs, and segmentation isolates them, preventing lateral movement in case of a compromise. This directly addresses the scenario of limiting a breach's impact.

Why the other options are wrong

  • A. MFA protects user access, but not internal microservice-to-microservice communication and data access post-authentication.
  • B. Automated incident response is reactive; the question asks about preventing widespread compromise.
  • C. While important for detection, centralized logging doesn't prevent a breach from spreading.

Least Privilege

A security principle where every user, process, and program is granted only the minimum permissions necessary to perform its function.

  • Reduces the attack surface.
  • Limits the 'blast radius' of a security breach.
  • Fundamental for zero-trust architectures.

Memory trick: Cloud Security: Protect Data, Isolate Threats, Respond Fast, Trust No One.

More Cloud Security questions