Courseiva
Cloud Application Security →mediumMultiple Choice

CCSP Cloud Application Security Practice Question

A cloud application development team is using a public API gateway to expose microservices. The security team wants to protect the APIs from common web vulnerabilities such as SQL injection and cross-site scripting (XSS). Which control should be implemented at the API gateway?

⚠ Common exam trap

The trap here is assuming that authentication or rate limiting controls also protect against injection attacks, when they operate at different layers and do not inspect payload content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web application firewall (WAF)

A web application firewall (WAF) deployed at the API gateway is the appropriate control to protect against SQL injection and XSS. It inspects HTTP requests and can block or sanitize malicious inputs before they reach the microservices. While other controls like rate limiting, mTLS, and OAuth 2.0 are important for availability, authentication, and authorization, they do not analyze request content for injection attacks. A WAF provides the necessary application-layer protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    API rate limiting

    Why it's wrong here

    Rate limiting controls the number of requests a client can make in a given time period, which helps prevent denial-of-service and brute-force attacks. However, it does not inspect the content of requests for malicious payloads like SQL injection or XSS. While important for availability, rate limiting alone cannot protect against injection vulnerabilities. A WAF is needed to analyze and filter request payloads for such threats.

  • ✗

    Mutual TLS (mTLS) authentication

    Why it's wrong here

    mTLS ensures that both the client and server authenticate each other using certificates, which is excellent for service-to-service authentication and encryption. However, it does not inspect application-layer data for injection attacks. Once a client is authenticated, mTLS does not prevent malicious payloads from reaching the backend. Therefore, it does not address SQL injection or XSS, which require content inspection.

  • ✓

    Web application firewall (WAF)

    Why this is correct

    A WAF inspects incoming HTTP requests and can block or sanitize malicious payloads that target vulnerabilities like SQL injection and XSS. Deploying a WAF at the API gateway provides a centralized enforcement point for all microservices, reducing the need to implement protections in each service. It can be configured with rule sets such as OWASP Core Rule Set to detect and mitigate common attacks, thus protecting the APIs from exploitation.

  • ✗

    OAuth 2.0 token validation

    Why it's wrong here

    OAuth 2.0 token validation verifies that a request carries a valid access token with appropriate scopes. It manages authorization and ensures only authorized clients can access APIs. However, it does not inspect the payload for malicious content. An attacker with a valid token could still send SQL injection or XSS payloads. Thus, OAuth 2.0 token validation alone does not protect against these vulnerabilities; a WAF is required.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.