Courseiva
mediumMultiple Select

CV0-004 Practice Question: Which TWO of the following are best practices for…

Which TWO of the following are best practices for securing an API gateway in a cloud environment?

⚠ Common exam trap

CompTIA often tests the misconception that 'detailed error messages help developers debug faster'—but in a cloud environment, exposing stack traces is a critical security flaw, not a best practice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement rate limiting to control the number of requests per client.

Option A is correct because rate limiting throttles the number of requests a client can make in a given time window, mitigating brute-force attacks, credential stuffing, and denial-of-service abuse against the gateway. Option D is correct because API keys or OAuth 2.0 tokens enforce authentication and authorization, ensuring only verified and properly scoped clients can invoke backend services. Option B is wrong because exposing endpoints without authentication allows anonymous abuse and data exposure, which is never a best practice. Option C is wrong because returning stack traces and detailed internal errors leaks implementation details useful to attackers; generic error messages should be returned instead. Option E is wrong because disabling HTTPS removes TLS encryption, exposing credentials and payloads to interception, and latency reduction does not justify that risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement rate limiting to control the number of requests per client.

    Why this is correct

    Rate limiting caps requests per client within a defined window, mitigating brute-force credential stuffing, enumeration and denial-of-service floods that would otherwise exhaust gateway and backend capacity. It satisfies the stem's cloud constraint, where internet-exposed gateways face untrusted, high-volume traffic that must be throttled before reaching origin services.

  • ✗

    Expose the API endpoints without authentication for ease of integration.

    Why it's wrong here

    Exposing endpoints unauthenticated lets any caller invoke backend services, bypassing the gateway's authorisation checks entirely. Anonymous access suits public, read-only resources such as status pages or open datasets, where no user identity or sensitive data is involved. Here, the stem demands securing the gateway, so authentication must remain enforced.

  • ✗

    Return detailed error messages including stack traces to help developers.

    Why it's wrong here

    Returning stack traces exposes internal implementation details, file paths and library versions to unauthenticated callers, giving attackers reconnaissance for targeted exploits. It is tempting because verbose diagnostics genuinely accelerate debugging during development, where a non-production gateway behind restricted access would legitimately benefit from detailed traces. In production, generic error responses with correlation IDs satisfy that need safely.

  • ✓

    Use API keys or OAuth for authentication and authorization.

    Why this is correct

    API keys identify the calling application, while OAuth issues scoped, time-limited tokens that authorise specific operations, so the gateway can authenticate callers and enforce least-privilege access per endpoint. This satisfies the stem's requirement to secure the gateway against anonymous or over-privileged requests in a cloud environment.

  • ✗

    Disable HTTPS to reduce latency.

    Why it's wrong here

    Disabling HTTPS strips TLS encryption and integrity protection from all gateway traffic, exposing credentials and payloads to interception; the stem asks for hardening practices. It is tempting because TLS handshakes add measurable latency, so disabling it would be considered only in isolated, non-production benchmarking where no sensitive data crosses the boundary.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.