Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityHard
A security auditor is reviewing the access control implementation for a cloud-based data lake containing highly sensitive customer information. The current setup relies solely on network-based access control lists (ACLs) to restrict access to the storage endpoints. What is the most significant security gap in this approach for protecting sensitive data in the cloud?
- ALack of centralized logging for ACL events
- BPerformance overhead introduced by ACL processing
- CDifficulty in managing ACLs across a distributed environment
- DACLs do not provide granular, identity-based authorization
Show answer & explanationAnswer & explanation
Correct answer: D. ACLs do not provide granular, identity-based authorization
Relying solely on network ACLs is a significant gap because they operate at the network layer (IP addresses, ports) and cannot provide granular, identity-based authorization (who can access what data, and what actions they can perform) which is critical for sensitive data. This allows any authenticated user or service from an allowed IP to access data, bypassing 'least privilege' for data objects.
Why the other options are wrong
- A. While centralized logging is important, it's a monitoring issue, not a fundamental flaw in the access control mechanism itself for data protection.
- B. Performance overhead is a operational concern, not a direct security gap regarding the effectiveness of data protection.
- C. Management difficulty is an operational challenge, not a fundamental security flaw in the protective capability of the ACLs themselves.
Identity-Based Access Control
A security mechanism that grants or denies access to resources based on the authenticated identity of the user or service, rather than just network attributes.
- Essential for 'least privilege' implementation.
- Often implemented using IAM roles, policies, and attributes.
- Provides granular control over data and application resources.
Memory trick: Data access needs identity, not just network gates.