Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium
A cloud security architect is integrating a new third-party security tool into their cloud environment. The tool requires programmatic access to create, modify, and delete virtual machines, network configurations, and storage buckets. What is the MOST secure way to grant this tool the necessary permissions, adhering to cloud security best practices?
- AGrant the tool full administrator access to the entire cloud account.
- BEmbed cloud provider access keys directly into the tool's configuration files.
- CCreate a dedicated Identity and Access Management (IAM) role with fine-grained permissions attached to the tool's service account.
- DUse a single, long-lived access key for a root user account.
Show answer & explanationAnswer & explanation
Correct answer: C. Create a dedicated Identity and Access Management (IAM) role with fine-grained permissions attached to the tool's service account.
Creating a dedicated IAM role with fine-grained permissions ensures the principle of least privilege is followed. This role can be assumed by the tool's service account, providing only the necessary access and no more, significantly reducing the blast radius if the tool is compromised. Access keys should not be embedded directly or used from root accounts.
Why the other options are wrong
- A. Granting full administrator access violates least privilege and creates a significant security risk.
- B. Embedding access keys directly is insecure as they can be easily compromised and are difficult to rotate.
- D. Using a root user account or long-lived access keys for programmatic access is a severe security anti-pattern and violates best practices.
Cloud Management Plane Security
Securing the control plane or management interface of a cloud environment, which allows users to provision, configure, and manage cloud resources.
- Relies heavily on Identity and Access Management (IAM).
- Requires strong authentication, authorization, and auditing.
- API security is paramount as most interactions are programmatic.
Memory trick: Roles for tools, no root rules.