Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud security team is deploying a web application with an API Gateway. Which TWO mechanisms should be implemented to protect against API abuse and unauthorized access?

⚠ Common exam trap

The trap here is selecting TLS enforcement as a security control for API abuse, confusing confidentiality with availability and access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rate limiting

Rate limiting (A) is correct because it throttles the number of requests a client can make in a given time window, directly mitigating API abuse such as brute-force attempts, credential stuffing, and denial-of-service floods that would otherwise overwhelm the gateway and backend. Authentication with JWT validation (E) is correct because it verifies the identity and integrity of the caller by validating the token's signature, issuer, audience, and expiry before granting access, thereby preventing unauthorized access to protected API routes. TLS enforcement (B) only encrypts data in transit and does not by itself stop abuse or authenticate API clients, so it does not satisfy the requirement. Resource tagging (C) is a metadata and governance mechanism for cost allocation and organization, not a runtime access control. VPC peering (D) provides private network connectivity between VPCs but does not protect an internet-facing API Gateway against abuse or unauthorized callers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Rate limiting

    Why this is correct

    Rate limiting caps request volume per client or API key, throttling brute-force attempts, credential stuffing and volumetric abuse before they reach backend services. It directly addresses the API abuse constraint by bounding how many calls an attacker can issue.

  • ✗

    TLS enforcement

    Why it's wrong here

    TLS enforcement encrypts data in transit but authenticates neither client nor caller identity, so it cannot prevent unauthorised API access or abuse. It is tempting because transport encryption is a standard API security control, and would be correct if the requirement were protecting confidentiality of credentials and payloads.

  • ✗

    Resource tagging

    Why it's wrong here

    Resource tagging is metadata for organisation, billing and governance; it enforces no authentication or rate limiting at the API Gateway. It is tempting because tags underpin attribute-based access control policies, and would be correct if the requirement were scoping IAM permissions by tag rather than blocking API abuse.

  • ✗

    VPC peering

    Why it's wrong here

    VPC peering connects private networks for internal routing; it provides no API authentication, authorisation or throttling at the gateway. It is tempting because network isolation is a security control, and would be correct if the requirement were private connectivity between VPCs rather than protecting a public API.

  • ✓

    Authentication (e.g., JWT validation)

    Why this is correct

    JWT validation at the API Gateway enforces authentication by verifying token signatures, issuer, audience and expiry before requests reach backend services. This directly satisfies the stem's requirement to block unauthorised access, since only callers holding tokens from the trusted identity provider, such as Microsoft Entra ID, are admitted.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.