A candidate must choose the right authentication and secrets-management mechanism for a given cloud workload and apply least privilege to serverless and container identities. The single most important thing is matching the control to the threat: use OAuth 2.0 for third-party API access and a managed secrets service for rotating credentials.
Start practicing
Cloud Application Security — choose a session length
Free · No account required
Domain overview
Cloud Application Security covers securing the software development lifecycle, APIs, identity, and runtime workloads in cloud environments. CCSP tests this through scenario questions on authentication choices, secrets management, serverless and container hardening, secure SDLC practices, and the shared responsibility boundary between provider-managed services and customer-implemented controls.
Exam objectives
Selecting OAuth 2.0, OpenID Connect, or SAML for API and partner authentication versus static API keys
Using AWS Secrets Manager, Azure Key Vault, or HashiCorp Vault for credential storage and rotation
Applying IAM roles and resource policies to scope AWS Lambda execution permissions and S3 triggers
Securing API keys and tokens by avoiding URL query strings and enforcing TLS with header-based transmission
Assuming API keys provide sufficient authorization for partner access when OAuth 2.0 scopes and token expiry are required for delegated, revocable access.
Embedding database credentials directly in container images or environment variables instead of using a managed secrets store with automatic rotation.
Granting Lambda functions broad wildcard IAM permissions rather than least-privilege roles scoped to specific S3 buckets and actions.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company is migrating a legacy application to the cloud. The application uses hardcoded database credentials. Which secure development practice should be implemented to address this?
2A security architect is designing a CI/CD pipeline for a cloud-native application. The team wants to automatically scan container images for vulnerabilities before deployment. Which of the following is the most effective approach?
3A SaaS provider uses a customer-managed encryption key (CMEK) model for data-at-rest. The provider's application runs in a multi-tenant cloud environment. Which attack surface is MOST directly mitigated by this approach?
4An organization is developing a mobile app that communicates with a cloud API. To ensure secure authentication, which of the following should be used?
5A cloud security team is implementing a Web Application Firewall (WAF) for a public-facing web application. The application uses a REST API with JSON payloads. Which of the following is the WAF's primary benefit?
6A company deploys microservices in Kubernetes. Each service communicates via gRPC with mutual TLS. A security assessment reveals that some services use self-signed certificates. What is the primary risk?
7A developer is tasked with securely storing a session token in a browser-based web application. Which storage mechanism is most secure?
8A company is implementing a serverless application using AWS Lambda. The function processes S3 events and writes to a DynamoDB table. Which of the following is the MOST secure way to grant the necessary permissions?
9Which TWO of the following are common best practices for securing cloud application APIs? (Choose two.)
10Which THREE of the following are essential components of a Secure Software Development Lifecycle (SSDLC) in the cloud? (Choose three.)
11Which TWO of the following are effective methods to protect against server-side request forgery (SSRF) in a cloud application? (Choose two.)
12Refer to the exhibit. A log entry shows a suspected SQL injection attack. Which security control would have prevented this attack?
13A financial services company uses a multi-region cloud deployment for its trading application. The application consists of a web frontend, a REST API, and a relational database. Recently, a penetration test revealed that an attacker could perform a time-based blind SQL injection through the API's search functionality. The injection allows the attacker to enumerate database contents by observing response times. The development team was already aware of the issue but had prioritized other features. The security team now demands immediate remediation. The application is critical and cannot be taken offline. Which of the following is the most effective immediate action to mitigate the risk without modifying the application code?
14A healthcare SaaS provider is deploying a new application that processes protected health information (PHI). The application uses a microservices architecture running on Kubernetes. Each microservice stores its data in a separate database. The compliance team requires that all data at rest be encrypted and that encryption keys be managed by the customer (CMEK). The cloud provider supports KMS with CMEK. However, the development team wants to use a single customer-managed key for all databases to simplify key management. The security architect is concerned about the blast radius if the key is compromised. Which of the following recommendations best balances security and operational efficiency?
15A cloud security architect is designing a CI/CD pipeline for a serverless application using AWS Lambda. The application processes sensitive user data and requires encryption at rest and in transit. Which of the following is the BEST approach to securely manage database credentials used by the Lambda function?
16A security team is implementing a web application firewall (WAF) for a cloud-based e-commerce application. The application is built on a microservices architecture and uses a RESTful API. Which of the following is the PRIMARY reason to deploy the WAF at the API gateway level rather than at the individual service level?
17A company is migrating a legacy monolithic application to a cloud-native microservices architecture. The security architect is concerned about securing inter-service communication. Which of the following should be implemented to ensure mutual authentication and encryption between services?
18An AWS S3 bucket policy is configured as shown in the exhibit. The security team wants to ensure that only requests from the corporate IP range (203.0.113.0/24) can read objects in the bucket. However, they notice that a CloudFront distribution configured to serve content from this bucket is returning 403 Forbidden errors. What is the MOST likely cause?
19A company is implementing a secure software development lifecycle (SSDLC) for its cloud-native applications. Which practice should be automated to detect vulnerabilities early in the development process?
20Which TWO of the following are primary objectives of a cloud application security program?
21Drag and drop the steps for conducting a cloud security risk assessment using the NIST CSF framework into the correct order.
22A cloud security architect is designing a multi-tier application that processes sensitive customer data. To protect data in transit between the web tier and the application tier, which of the following is the MOST appropriate approach?
23A DevSecOps team is integrating static application security testing (SAST) into their CI/CD pipeline. Which of the following is the PRIMARY benefit of performing SAST during the build phase rather than later in the pipeline?
24A company is deploying a containerized application on Kubernetes. The security team requires that containers run with the least privilege, and that any attempt to escalate privileges within a container is blocked. Which Kubernetes security context setting should be applied to the pod specification?
25A security analyst is reviewing application logs and notices that a large number of requests from a single IP address are attempting to access a REST API endpoint with invalid session tokens. Which cloud-based mitigation is MOST effective at blocking such automated attacks?
26A financial services company is adopting a cloud-native microservices architecture. They want to ensure that only authorized services can communicate with each other, and that all inter-service communication is encrypted. Which of the following is the BEST approach?
27An organization is migrating a legacy application to the cloud and plans to use a cloud access security broker (CASB). Which of the following is the PRIMARY function of a CASB in securing cloud applications?
28A company is adopting DevSecOps and wants to incorporate security testing into their continuous integration pipeline. They have decided to run SAST (static analysis) and SCA (software composition analysis) tools. Which of the following is the PRIMARY reason for including SCA in addition to SAST?
29Which TWO of the following are secure coding practices that help prevent injection attacks?
30Which THREE of the following are common challenges in securing serverless applications?
31Which THREE of the following are effective controls to secure a RESTful API in the cloud?
32A security team is reviewing a cloud application's CI/CD pipeline. They want to ensure that only approved open-source libraries are used in production builds. Which approach best addresses this requirement?
33An organization uses a multi-cloud architecture with applications running on both AWS and Azure. They need to implement a secrets management solution that works across both platforms and supports automated rotation. Which approach best meets these requirements?
34A security engineer is investigating an incident where an attacker exploited a server-side request forgery (SSRF) vulnerability in a cloud application. The application runs in a cloud environment and uses internal metadata endpoints. Which mitigation should be prioritized to prevent future SSRF attacks?
35A company is adopting a serverless architecture using AWS Lambda. The security team is concerned about potential injection attacks via event payloads. Which practice is most effective at mitigating such attacks?
36A cloud application uses containers orchestrated by Kubernetes. The security team wants to enforce that containers cannot run as root and that file systems are read-only at runtime. Which Kubernetes security context configuration should be applied?
37A cloud application uses a RESTful API that handles payment transactions. The security team identifies that the API is vulnerable to brute-force attacks on the authentication endpoint. Which control should be implemented to mitigate this?
38An organization uses infrastructure as code (IaC) to deploy cloud resources. The security team wants to prevent misconfigurations such as open security groups from being deployed. Which two practices should be integrated into the IaC pipeline? (Select TWO)
39A cloud application uses a service mesh for inter-service communication. The security team wants to enforce mutual TLS (mTLS) between all services and ensure that service identities are verified. What is the most effective way to achieve this?
40A security architect is designing access controls for a cloud-based microservices application. Which approach best aligns with the principle of least privilege for service-to-service authentication?
41A development team is migrating a legacy application to the cloud. Which security testing approach should be adopted early in the CI/CD pipeline to catch vulnerabilities as code is written?
42A cloud security engineer needs to ensure that a containerized application running in a Kubernetes cluster securely stores and rotates database credentials. Which is the most appropriate solution?
43During a code review, a developer identifies that an application uses input from an HTTP request to generate a SQL query string. What is the primary security concern?
44An organization deploys a serverless application using AWS Lambda functions that access an RDS database. Which practice best ensures that the database credentials are protected?
45Which of the following is a key benefit of using a software composition analysis (SCA) tool in a cloud application security program?
46A company wants to enforce that all API calls to its cloud services are authenticated and authorized. Which design pattern should be implemented?
47A DevOps team wants to prevent insecure code from being deployed to production. Which gate should be implemented in the CI/CD pipeline?
48Which TWO measures are effective for securing container images in a cloud environment?
49Which THREE are best practices for implementing secrets management in cloud applications?
50Which TWO practices help protect against insecure deserialization attacks in cloud applications?
51An IAM policy named S3ReadOnlyAccess has DefaultVersionId v3. What does this indicate?
52A cloud security engineer reviews this Terraform configuration for a security group. Which change is necessary to improve security?
53A company develops a microservices application and wants to ensure secrets such as API keys and database credentials are not exposed in container images. Which approach best meets this requirement?
54A SaaS application allows users to upload profile pictures. The development team wants to prevent upload of malicious files that could compromise the server. Which control is most effective?
55A cloud application uses OAuth 2.0 for authorization. What is the primary purpose of using a refresh token in this flow?
56An organization uses a CI/CD pipeline that automatically builds and deploys container images to a Kubernetes cluster. A security scanner flags that the base image contains a critical vulnerability. What is the best course of action to prevent vulnerable images from being deployed?
57A developer wants to ensure that sensitive data in a cloud database is protected even if the database backup files are stolen. Which best practice should be implemented?
58A cloud security engineer is reviewing the authentication mechanism for a web application. The application currently uses API keys transmitted in the URL query string. What is the primary security concern with this approach?
59Which of the following is the best way to protect a web application from cross-site scripting (XSS) attacks?
60A company uses a serverless architecture with AWS Lambda to process user-uploaded files. The Lambda function is triggered by an S3 bucket event. While reviewing security, the architect wants to ensure that the Lambda function cannot be invoked by unauthorized S3 buckets or accounts. What is the most secure configuration?
61Which TWO of the following are considered best practices for securing containerized applications in a cloud environment?
62Which THREE of the following are valid techniques to protect application programming interfaces (APIs) from abuse?
63A company is moving a legacy application to the cloud. The application uses hard-coded passwords for database connections. Which secure development practice should be implemented to address this issue?
64A cloud application experiences intermittent failures during peak load. Logs show database connection timeouts. Which architecture change would best address this issue?
65A software company develops an API for third-party integrations. They want to ensure that only authorized partners can access the API. Which authentication mechanism is most appropriate?
66A team is adopting DevSecOps. Which practice best integrates security into the development lifecycle?
67Which TWO best practices help secure a cloud application's runtime environment?
68Which TWO are effective strategies for securing cloud application data at rest?
69Which THREE are key considerations when designing a secure software development lifecycle (SSDLC) for cloud applications?
70A company runs a multi-tier cloud application with a web frontend, an API layer, and a database. The application uses OAuth 2.0 for authentication. Recently, users have been experiencing session hijacking attacks. Upon investigation, the security team finds that session tokens are being intercepted in transit. The application uses HTTPS for all communications, but a developer discovers that the application is also accessible via HTTP due to a misconfiguration. The team wants to implement additional security controls to prevent token theft. Which course of action should be taken first?
71A security architect is designing a cloud-native application using microservices. They decide to implement mutual TLS (mTLS) for service-to-service communication in a Kubernetes cluster with hundreds of services. What is the primary challenge in managing mTLS certificates in this dynamic environment?
72A security team is reviewing controls for a cloud application that transmits personally identifiable information (PII) over the internet. Which TWO controls are essential for protecting data in transit?
73A healthcare SaaS company runs containerized microservices on Google Kubernetes Engine (GKE). The security team scans containers with a vulnerability scanner and finds that base images have several critical vulnerabilities. The container build process uses a Dockerfile that pulls the latest Ubuntu image from Docker Hub. The team wants to reduce the attack surface without delaying feature releases. What is the best approach?
74A large enterprise is migrating a legacy .NET application to Azure App Service. The application currently stores session state in-memory on the web server. During the migration, the team plans to horizontally scale the application across multiple instances. The security team requires that session data remain confidential and be available even if an instance fails. Which solution should the team implement?
75A financial services company deploys a containerized application on Amazon ECS with Fargate. The application needs to access an encrypted RDS database. The security policy mandates that database credentials must never be stored in the application code or configuration files and must be rotated automatically every 90 days. Which solution should the DevOps team implement to satisfy these requirements?
76A software company develops a mobile application that communicates with a cloud backend using REST APIs. The application uses OAuth 2.0 with the authorization code grant and PKCE for authentication. After a security audit, the team identifies that the backend API accepts both a client secret (from the authorization code grant) and a PKCE code verifier. The security team wants to remove unnecessary attack surface. Which change should be made?
77A cloud security architect is designing a CI/CD pipeline for a containerized application. The requirement is that container images be cryptographically signed by the build system and that only images with valid signatures be admitted to the production Kubernetes cluster. Which combination of controls best achieves this?
78A cloud team is building a web application that stores user session tokens in the browser. A security review recommends that the tokens be inaccessible to JavaScript to reduce the impact of cross-site scripting attacks. Which cookie attribute should be set on the session token?
79A cloud-native application team is adopting a secrets management service to eliminate hardcoded credentials in source code and configuration files. Which two practices best align with secure secrets management in the cloud? (Choose two.)
80A cloud security engineer is reviewing the security posture of a web application deployed on AWS. The application uses an Application Load Balancer (ALB) and EC2 instances. The engineer wants to ensure that all incoming traffic is encrypted in transit. Which action should the engineer take?
81A cloud application uses an API gateway to expose backend microservices. The security team wants to ensure that clients cannot bypass the gateway and call backend services directly. Which control should be implemented to enforce this?
82A cloud-native application uses a microservices architecture deployed on Kubernetes. The security team wants to ensure that only authorized services can communicate with each other, and that communication is encrypted. Which Kubernetes feature should be used to meet these requirements?
83A healthcare SaaS provider exposes REST APIs to partner clinics. The security team must ensure that the API cannot be abused by replaying captured requests. The API already uses TLS 1.3 and OAuth 2.0 bearer tokens with short lifetimes. Which additional control best mitigates replay attacks against the API?
84A cloud operations team is building a CI/CD pipeline that deploys container images to a managed Kubernetes cluster. Security policy requires that only images whose vulnerabilities have been scanned and approved can run. The team wants the cluster itself to refuse any pod that references an unapproved image, even if the pipeline is bypassed. Which mechanism should they implement?
85A retail company is migrating its monolithic e-commerce application to containers on a managed Kubernetes service. The security architect wants to ensure that if a container is compromised, the attacker cannot use the container's credentials to access the underlying node's filesystem or other pods' volumes. Which Kubernetes feature should be configured to meet this requirement?
86A cloud team is designing a new microservices application deployed on a managed Kubernetes service. The security architect requires that all service-to-service traffic be encrypted with mutual TLS (mTLS) without modifying application code. Which cloud-native component should be implemented to meet this requirement?
87A healthcare organization runs a multi-tenant SaaS application on a public cloud. Each tenant's data is stored in a shared database with a tenant identifier column. A penetration test shows that a crafted API request can return records belonging to another tenant. The application already authenticates users and validates their tenant membership at login. Which control most directly addresses the root cause of this finding?
88A healthcare company runs a containerized patient portal on a managed Kubernetes service. Security policy requires that every container image be cryptographically verified as coming from the company's internal build pipeline before any pod is admitted to the cluster. The images are stored in a private OCI registry, and each build produces a signature using a private key held in a cloud key management service. Which mechanism should be implemented to enforce this policy at admission time?
89A cloud-native payroll application stores employee bank details in a managed database. The security team wants to ensure that even if the database storage is compromised, the data cannot be read without explicit decryption. They also need to minimize changes to the application code. Which approach best meets these requirements?
90A company is migrating a legacy web application to the cloud. The application uses a relational database. The security team wants to ensure that database credentials are never hardcoded in the application and are automatically rotated. Which cloud-native approach should be used?
91A cloud security engineer is reviewing the software development lifecycle for a team building a containerized application on a public cloud. The team wants to shift security left and reduce vulnerabilities in production images. Which two practices should be implemented to achieve this? (Choose two.)
92A development team is building a web application that stores user passwords. The security architect recommends using a password hashing algorithm with a tunable work factor and a per-user random salt. Which approach best meets this recommendation?
93A cloud application team is designing a multi-tenant SaaS platform on a public cloud. Tenant data is stored in a shared database, and the application uses a single service account to connect. During a threat modeling session, the security architect raises concerns that a coding error could allow one tenant to read another tenant's records. Which control should be implemented to provide defense in depth against this cross-tenant data access risk?
94A media company uses a CI/CD pipeline to deploy a web application to a cloud platform. The security team wants to integrate security testing that can detect vulnerabilities in third-party libraries and base images before deployment, without significantly slowing the pipeline. Which practice should be implemented?
95A cloud team is integrating a third-party analytics service into its application. The vendor requires access to data in the organization's object storage bucket. Security policy forbids sharing long-lived cloud credentials with third parties. Which approach best satisfies the policy while granting the vendor the required access?
96A healthcare company runs a containerized patient portal on a managed Kubernetes service. The security team needs to ensure that container images cannot be deployed if they contain known critical vulnerabilities. The build pipeline already produces an SBOM. Which control should be enforced at the admission layer to meet this requirement?
97A cloud application uses a managed API gateway to expose REST APIs. The security team wants to ensure that clients cannot bypass the gateway and call backend services directly. The backend services run on private subnets and are fronted by an internal load balancer. Which control should be implemented to enforce this requirement?
98A company is building a cloud-native API that uses OAuth 2.0 for delegated authorization. The security team wants to harden the authorization code flow against token interception and misuse. Which two measures should be implemented to protect the authorization code and tokens? (Choose two.)
99A cloud security team is designing a secure software development lifecycle (SDLC) for a new microservices application deployed to a public cloud. They want to ensure that security is embedded throughout development and operations. Which two practices should be implemented to achieve this? (Choose two.)
100A cloud-native SaaS provider uses OpenID Connect (OIDC) for user authentication. The security architect wants to reduce the impact of stolen authorization codes and ensure that tokens issued to a single-page application cannot be replayed by a different client. Which OIDC mechanism should be implemented?
101A development team is building a cloud-native application that stores user session data in a managed Redis service. The security architect requires that session data be encrypted at rest and that the application authenticate to Redis without embedding static credentials in code. Which approach best meets these requirements?
102A security team is reviewing the software development lifecycle for a cloud-native application. They want to shift security left and reduce the cost of remediating defects. Which two practices best support this goal? (Choose two.)
103A cloud operations team is deploying a web application that stores configuration files and application logs in an object storage bucket. The security policy requires that data be encrypted at rest, and the team wants the cloud provider to manage the encryption keys with minimal operational overhead. The bucket must remain accessible to the application without code changes. Which approach should the team use?
104A security engineer is reviewing a cloud application that uses OAuth 2.0 to delegate access to a third-party API. The application is a single-page application (SPA) running in the browser. The engineer wants to prevent authorization code interception and ensure that the client cannot impersonate another client. Which OAuth 2.0 enhancement should be implemented?
105A cloud security team is reviewing a CI/CD pipeline that builds and deploys a containerized application to a production cluster. The pipeline runs in a cloud build service and uses a long-lived service account key stored as a secret in the pipeline configuration to push images and update deployments. A recent audit flagged this as a risk. Which change best reduces the risk of credential compromise while maintaining automated deployments?
106A development team is building a cloud application that stores sensitive customer data in a managed database service. The security policy requires that data be encrypted at rest with keys that the organization controls and can rotate independently of the cloud provider. Which approach meets this requirement?
107A retail company migrates its customer-facing web application to a cloud environment. The security team wants to ensure that security testing is integrated throughout the software development lifecycle (SDLC) rather than only before production deployment. Which approach best aligns with this goal?
108A cloud application team is adopting a DevSecOps pipeline for a containerized workload. They want to integrate security testing that can detect vulnerable dependencies and misconfigured infrastructure-as-code templates before deployment. Which two practices should be implemented to meet these goals? (Choose two.)
109A cloud security engineer is reviewing a serverless application built with AWS Lambda. The function processes messages from an Amazon SQS queue and writes to an Amazon DynamoDB table. The engineer needs to ensure that the Lambda function has only the necessary permissions to perform its tasks. Which approach best follows the principle of least privilege?
110A cloud provider's API is used by an application to retrieve secrets from a managed secrets store. The security team wants to ensure that if a secret is compromised, its use is limited to a short window and that all access is attributable to a specific workload identity. Which combination best meets these requirements?
111A security architect is designing a multi-tenant SaaS application hosted on AWS. The application uses a shared Amazon RDS database with a tenant_id column to isolate data. The architect must ensure that tenants cannot access each other's data even if there is a vulnerability in the application layer. Which additional control should be implemented to enforce data isolation at the database level?
112A development team is building a cloud application and needs to store API keys and database passwords securely. The team wants to minimize management overhead and ensure automatic rotation of secrets. Which AWS service should they use?
113A cloud application uses a microservices architecture deployed on Kubernetes. The security team wants to enforce that only signed container images from a trusted registry can be deployed to the cluster. Which Kubernetes feature should be used to achieve this?
114A cloud application development team is using a public API gateway to expose microservices. The security team wants to protect the APIs from common web vulnerabilities such as SQL injection and cross-site scripting (XSS). Which control should be implemented at the API gateway?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
A candidate must choose the right authentication and secrets-management mechanism for a given cloud workload and apply least privilege to serverless and container identities. The single most important thing is matching the control to the threat: use OAuth 2.0 for third-party API access and a managed secrets service for rotating credentials.
The Courseiva CCSP question bank contains 114 questions in the Cloud Application Security domain, covering the 17% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cloud Application Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included