Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud security architect is hardening the metadata service on a fleet of EC2 instances that host a customer-facing web application. The team wants to reduce the risk of server-side request forgery leading to credential theft, while keeping the application's legitimate ability to retrieve instance role credentials. Which TWO measures should the architect implement? (Choose two.)

⚠ Common exam trap

The trap here is believing that tightening the IAM role's permissions neutralizes SSRF credential theft, when the exposure is the metadata endpoint itself and the credentials remain retrievable regardless of how narrowly scoped they are.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the instance metadata service hop limit to 1 so responses cannot traverse additional network hops.

Requiring IMDSv2 forces token-based requests that SSRF payloads generally cannot produce, and a hop limit of 1 stops metadata responses from being relayed through proxies or container layers. Together they harden the endpoint while preserving legitimate role credential retrieval. The remaining choices either fail to block the retrieval path or break required functionality.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the instance metadata service hop limit to 1 so responses cannot traverse additional network hops.

    Why this is correct

    A hop limit of 1 prevents metadata responses from being forwarded beyond the instance itself, defeating the common attack pattern where a proxy or container layer relays the request. Combined with token enforcement it closes both the request-forging and the forwarding path, and it does not interfere with direct metadata calls made by the application on the instance.

  • ✗

    Enable AWS CloudTrail data events on the S3 bucket that stores application logs.

    Why it's wrong here

    CloudTrail data events record object-level API activity against S3, which provides audit evidence about log access but has no effect on the EC2 metadata endpoint or on SSRF behavior. It does not require tokens, does not change hop limits, and cannot prevent an attacker from retrieving role credentials through a forged request. This is unrelated to the risk described.

  • ✗

    Attach an IAM role with a permissions boundary that denies all actions except those the application needs.

    Why it's wrong here

    A permissions boundary limits what stolen credentials can do, which is useful defense in depth, but it does not stop the credentials from being retrieved in the first place. The scenario asks to reduce SSRF-driven credential theft and preserve legitimate retrieval, and boundaries leave the exposure path fully intact. This is a least-privilege control, not a metadata hardening control.

  • ✓

    Enforce IMDSv2 by setting the instance metadata options to require tokens (HttpTokens: required).

    Why this is correct

    Requiring IMDSv2 means every metadata request must first obtain a session token via a PUT request, which a typical SSRF vector cannot craft or forward. This blocks the classic credential-theft path while leaving the application able to fetch role credentials normally, directly addressing the stated risk without breaking legitimate metadata access.

  • ✗

    Disable the instance metadata service entirely on all web application instances.

    Why it's wrong here

    Disabling IMDS does prevent credential retrieval through the metadata endpoint, but it also breaks the application's legitimate need to obtain instance role credentials, which the scenario explicitly requires preserving. The team would have to hardcode or otherwise distribute credentials, increasing risk. This over-corrects rather than hardening the service.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.