- Home
- All questions
- Question 605
CompTIA Security+ study material · question 605 of 611
Why should a secret be scoped to the smallest set of workloads that need it?
Show the answer
Answer: D. So one compromised workload does not expose credentials belonging to unrelated services
Broad scoping turns one compromise into many, which is the same reasoning as least privilege applied to secrets.
Source: OWASP Secrets Management Cheat Sheet (OWASP) — OWASP Secrets Management Cheat Sheet › Access Control