問題文
A team gives its pipeline key permission to upload results, when a read-only key would have sufficed for their use. What have they given away?
選択肢
- The ability to pin the tool to a specific version, since a key that is allowed to write is refused by every release except the newest one that has been published.
- The ability to run local-only scans, as a key with upload permission always transmits its results and the tool refuses to run in a mode that would discard them once such a key has been configured.
- The ability to keep the pipeline from writing into the tenant, since the broader permission also lets anything holding that key change stored data.
- The ability to use the tool at all, because upload permission is incompatible with pipeline use, so the step would fail on the very first call it makes.