CCSP Cloud Application Security Practice Question
A cloud application development team is using a public API gateway to expose microservices. The security team wants to protect the APIs from common web vulnerabilities such as SQL injection and cross-site scripting (XSS). Which control should be implemented at the API gateway?
⚠ Common exam trap
The trap here is assuming that authentication or rate limiting controls also protect against injection attacks, when they operate at different layers and do not inspect payload content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web application firewall (WAF)
A web application firewall (WAF) deployed at the API gateway is the appropriate control to protect against SQL injection and XSS. It inspects HTTP requests and can block or sanitize malicious inputs before they reach the microservices. While other controls like rate limiting, mTLS, and OAuth 2.0 are important for availability, authentication, and authorization, they do not analyze request content for injection attacks. A WAF provides the necessary application-layer protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
API rate limiting
Why it's wrong here
Rate limiting controls the number of requests a client can make in a given time period, which helps prevent denial-of-service and brute-force attacks. However, it does not inspect the content of requests for malicious payloads like SQL injection or XSS. While important for availability, rate limiting alone cannot protect against injection vulnerabilities. A WAF is needed to analyze and filter request payloads for such threats.
- ✗
Mutual TLS (mTLS) authentication
Why it's wrong here
mTLS ensures that both the client and server authenticate each other using certificates, which is excellent for service-to-service authentication and encryption. However, it does not inspect application-layer data for injection attacks. Once a client is authenticated, mTLS does not prevent malicious payloads from reaching the backend. Therefore, it does not address SQL injection or XSS, which require content inspection.
- ✓
Web application firewall (WAF)
Why this is correct
A WAF inspects incoming HTTP requests and can block or sanitize malicious payloads that target vulnerabilities like SQL injection and XSS. Deploying a WAF at the API gateway provides a centralized enforcement point for all microservices, reducing the need to implement protections in each service. It can be configured with rule sets such as OWASP Core Rule Set to detect and mitigate common attacks, thus protecting the APIs from exploitation.
- ✗
OAuth 2.0 token validation
Why it's wrong here
OAuth 2.0 token validation verifies that a request carries a valid access token with appropriate scopes. It manages authorization and ensures only authorized clients can access APIs. However, it does not inspect the payload for malicious content. An attacker with a valid token could still send SQL injection or XSS payloads. Thus, OAuth 2.0 token validation alone does not protect against these vulnerabilities; a WAF is required.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.