hardMultiple Choice
CCSP Practice Question: A cloud security architect is designing an API…
A cloud security architect is designing an API gateway for a microservices application. The gateway must authenticate requests, enforce rate limiting, and log all transactions for audit. Which of the following security controls is most critical to protect against API abuse?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement rate limiting and throttling based on client identity and request volume.
Rate limiting and throttling directly prevent API abuse by limiting request frequency based on client identity and volume. Option B is incorrect because encryption protects data in transit but does not prevent abuse. Option C is incorrect because input validation prevents injection attacks but not volume-based abuse. Option D is incorrect because API keys authenticate clients but do not limit usage; rate limiting is required for abuse protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement rate limiting and throttling based on client identity and request volume.
Why this is correct
Rate limiting and throttling keyed to client identity directly counters API abuse by capping request volume per consumer, mitigating credential-stuffing, scraping and denial-of-service bursts. It satisfies the stem's enforcement requirement while complementing authentication and audit logging, making it the most critical control against abusive API usage patterns.
- ✗
Use TLS 1.3 to encrypt all traffic between clients and the gateway.
Why it's wrong here
TLS 1.3 encrypts data in transit, protecting confidentiality and integrity, but it authenticates neither the client nor the request volume, so an attacker with a valid session can still flood the gateway. Transport encryption is the right control when the threat is interception or tampering, not abuse.
- ✗
Validate and sanitize all input parameters to prevent injection attacks.
Why it's wrong here
Input validation blocks injection payloads reaching backend services, yet it does not limit request frequency, so credential-stuffing or enumeration floods pass through untouched. Sanitising parameters is correct when the threat is malformed data corrupting queries, not the request rate itself.
- ✗
Require API keys for all requests and revoke keys of suspicious clients.
Why it's wrong here
API keys identify the calling application but are static shared secrets, so a leaked or embedded key grants full access until revoked; they cannot stop volumetric abuse from many distinct clients. API keys suit simple partner identification, not the dynamic per-client throttling and anomaly detection this scenario demands.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.