Courseiva
Cloud Application Security →mediumMultiple Choice

CCSP Cloud Application Security Practice Question

A cloud application uses an API gateway to expose backend microservices. The security team wants to ensure that clients cannot bypass the gateway and call backend services directly. Which control should be implemented to enforce this?

⚠ Common exam trap

The trap here is assuming that strong gateway controls like mutual TLS or rate limiting also prevent direct backend access, when only network isolation of the backends enforces the gateway path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the backend services in a private subnet and restrict inbound traffic to only the API gateway's security group or identity.

Enforcing that backend services accept traffic only from the API gateway requires network-level restriction, such as private subnets combined with security group or identity-based rules. Authentication, rate limiting, and logging at the gateway improve security but do not prevent a client from reaching a backend endpoint that remains exposed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure rate limiting on the API gateway to prevent clients from sending excessive requests.

    Why it's wrong here

    Rate limiting protects backend services from traffic spikes but does not prevent a client from contacting a backend endpoint directly. A determined client could bypass the gateway entirely, so rate limiting alone cannot enforce the gateway as the only path.

  • ✓

    Place the backend services in a private subnet and restrict inbound traffic to only the API gateway's security group or identity.

    Why this is correct

    By making backend services reachable only from the API gateway's network identity, direct client access is blocked. This enforces the gateway as the single entry point and ensures all requests pass through the gateway's authentication, throttling, and logging controls.

  • ✗

    Enable mutual TLS on the API gateway so clients must present certificates to connect.

    Why it's wrong here

    Mutual TLS authenticates clients at the gateway but does not stop a client from discovering and calling a backend service endpoint directly if that service remains reachable. The bypass risk persists unless network access to the backend is restricted.

  • ✗

    Enable access logging on the API gateway and forward logs to a central monitoring service.

    Why it's wrong here

    Access logging provides visibility into requests that traverse the gateway, but it is detective rather than preventive. It does not block direct calls to backend services, so it cannot enforce that all traffic passes through the gateway.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.