Certified Cloud Security Professional (CCSP)Cloud Application SecurityEasy
A cloud service provider offers various APIs for managing its infrastructure. A customer wants to automate the deployment and management of their cloud resources using these APIs. To ensure the principle of least privilege, how should the customer manage the API credentials used by their automation scripts?
- AEmbed the full administrator API keys directly within the automation scripts.
- BCreate specific IAM roles with only the necessary permissions for each automation task and use temporary credentials.
- CStore a single, highly privileged API key in an encrypted file on the automation server.
- DUse the root account's API keys for all automation tasks to simplify management.
Show answer & explanationAnswer & explanation
Correct answer: B. Create specific IAM roles with only the necessary permissions for each automation task and use temporary credentials.
Creating specific IAM roles with granular permissions and using temporary credentials directly implements the principle of least privilege and enhances security by reducing the impact of a compromised credential.
Why the other options are wrong
- A. Embedding administrator API keys is highly insecure as it provides broad access and makes them easily discoverable.
- C. Storing a single, highly privileged API key, even encrypted, still poses a significant risk if the encryption key or the server is compromised.
- D. Using root account API keys is extremely dangerous and violates all security best practices, as it grants unrestricted access to the entire cloud account.
API Credential Management
The secure handling of API keys, tokens, and other credentials used to authenticate and authorize access to APIs, especially for automated processes.
- Adhere to least privilege.
- Use temporary credentials when possible.
- Avoid hardcoding credentials.
Memory trick: API Bots: 'Temporary Roles' for temporary tasks, never 'Root'.