Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
A cloud application needs to communicate with external APIs from different vendors. Each external API has its own authentication mechanism (e.g., OAuth 2.0, API key in header, custom token). To simplify secure access for the application developers and centralize credential management, what is the most appropriate solution?
- AImplement a custom proxy service that translates and manages authentication for each external API.
- BHardcode credentials for each external API directly into the application's configuration files.
- CCreate a separate IAM role for each external API and assign it to the application.
- DStore all external API credentials in a cloud-based Secrets Management Service.
Show answer & explanationAnswer & explanation
Correct answer: D. Store all external API credentials in a cloud-based Secrets Management Service.
A cloud-based Secrets Management Service is designed to securely store, manage, and retrieve diverse credentials (like API keys, OAuth tokens) for various external services. It centralizes management, allows for rotation, and integrates with IAM for access control, simplifying secure access for developers.
Why the other options are wrong
- A. A custom proxy service could work but introduces significant development and maintenance overhead, whereas a dedicated secrets management service is a mature, off-the-shelf solution.
- B. Hardcoding credentials is a severe security risk and makes rotation and management extremely difficult.
- C. IAM roles are for granting permissions to cloud resources within the same cloud provider, not for managing credentials for external, third-party APIs with different authentication mechanisms.
Secrets Management for External APIs
Using a dedicated secrets management service to securely store, retrieve, and manage credentials (e.g., API keys, tokens) required for an application to interact with external, third-party APIs.
- Centralizes diverse credential types.
- Enhances security by separating credentials from code.
- Supports automated rotation and auditing.
Memory trick: Secrets Manager safeguards all API secrets.