Study. uk . com
  1. Home
  2. All questions
  3. Question 605

CompTIA Security+ study material · question 605 of 611

Why should a secret be scoped to the smallest set of workloads that need it?

  1. To simplify the audit trail
  2. To allow a longer rotation interval
  3. To reduce the secrets platform's storage cost
  4. So one compromised workload does not expose credentials belonging to unrelated services
Show the answer

Answer: D. So one compromised workload does not expose credentials belonging to unrelated services

Broad scoping turns one compromise into many, which is the same reasoning as least privilege applied to secrets.

Source: OWASP Secrets Management Cheat Sheet (OWASP) — OWASP Secrets Management Cheat Sheet › Access Control

Challenge yourself on this topic → Study as cards