nerdexam
CSA

CCSK · Question #126

What are major factors to building and managing a secure management plane?

The correct answer is A. Perimeter security; customer authentication; internal authentication and credential passing. Building a secure management plane requires layered controls spanning perimeter defenses, customer-facing authentication, and internal credential handling.

Cloud Platform and Infrastructure Security

Question

What are major factors to building and managing a secure management plane?

Options

  • APerimeter security; customer authentication; internal authentication and credential passing;
  • BAPI management; end point security; logging; and authentication and authorization
  • CDevice patching and maintenance; internal authentication and credential passing; access
  • DPerimeter security; customer authentication; internal authentication and credential passing;
  • EPerimeter patching; log authentication; external entitlement passing; credential alerting and

How the community answered

(48 responses)
  • A
    75% (36)
  • B
    15% (7)
  • C
    2% (1)
  • D
    2% (1)
  • E
    6% (3)

Why each option

Building a secure management plane requires layered controls spanning perimeter defenses, customer-facing authentication, and internal credential handling.

APerimeter security; customer authentication; internal authentication and credential passing;Correct

Choice A correctly identifies the foundational pillars of management plane security: perimeter security to control access at the boundary, customer authentication to verify who accesses management interfaces, and internal authentication with secure credential passing to protect communications between management services - together covering the full trust boundary of the management layer.

BAPI management; end point security; logging; and authentication and authorization

API management and endpoint security are valid concerns but belong primarily to the application and data plane layers, not the core management plane security model.

CDevice patching and maintenance; internal authentication and credential passing; access

Device patching is a maintenance activity and omits perimeter security and customer authentication, which are essential boundary controls for the management plane.

DPerimeter security; customer authentication; internal authentication and credential passing;

Choice D begins identically to A but diverges in its complete list of factors, making it an incomplete representation of the full management plane security framework.

EPerimeter patching; log authentication; external entitlement passing; credential alerting and

Terms like 'perimeter patching,' 'log authentication,' and 'external entitlement passing' do not correspond to recognized management plane security concepts and are factually inaccurate.

Concept tested: Secure cloud management plane key security factors

Source: https://cloudsecurityalliance.org/research/guidance/

Topics

#management plane security#perimeter security#authentication#authorization

Community Discussion

No community discussion yet for this question.

Full CCSK Practice