Courseiva

CCSP Cloud Application Security Practice Question

A cloud security team is designing a secure software development lifecycle (SDLC) for a new microservices application deployed to a public cloud. They want to ensure that security is embedded throughout development and operations. Which two practices should be implemented to achieve this? (Choose two.)

⚠ Common exam trap

The trap here is equating a single late-stage activity or centralizing security ownership with embedding security throughout the lifecycle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct threat modeling during the design phase for each microservice.

Embedding security throughout the SDLC requires proactive design-time analysis and automated enforcement in delivery. Threat modeling during design surfaces risks before code exists, while automated CI/CD security gates ensure every build meets policy and blocks critical findings. Together they shift security left and maintain it through deployment. Production-only testing, centralized ownership, and reduced logging all weaken or delay security rather than integrating it continuously.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conduct threat modeling during the design phase for each microservice.

    Why this is correct

    Threat modeling in the design phase identifies potential threats, attack surfaces, and required mitigations before code is written. For microservices, it clarifies trust boundaries between services, data flows, and authentication needs. This early analysis reduces costly rework and aligns security with architecture, making it a core practice for embedding security throughout the SDLC.

  • ✗

    Assign all security responsibilities exclusively to a centralized security team.

    Why it's wrong here

    Centralizing all security work in one team creates bottlenecks and disconnects security from development velocity. Modern SDLC practice, often called DevSecOps, distributes security ownership to development teams with security team enablement. This option reduces shared responsibility and slows feedback, so it does not embed security throughout development and operations.

  • ✓

    Automate security gates in the CI/CD pipeline that block builds on critical findings.

    Why this is correct

    Automated security gates run SAST, SCA, secret scanning, and image checks on every build and fail the pipeline on policy violations. This enforces consistent security checks without relying on manual reviews and gives developers fast feedback. It operationalizes security in the SDLC and prevents vulnerable artifacts from reaching production, directly supporting the objective.

  • ✗

    Disable detailed logging in production to reduce storage costs and improve performance.

    Why it's wrong here

    Reducing logging undermines detection, incident response, and forensic analysis, which are essential to operating securely. Security monitoring depends on comprehensive logs from applications, infrastructure, and cloud services. Disabling logs to save cost weakens the security posture and conflicts with the goal of embedding security throughout operations.

  • ✗

    Perform a full penetration test only after the application is deployed to production.

    Why it's wrong here

    Testing only after production deployment is too late; vulnerabilities found then are costly to fix and may already be exposed. It also does not embed security throughout development. While production testing has value, relying on it alone contradicts the goal of integrating security earlier in the lifecycle and addressing issues before release.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.