CCSP Cloud Application Security Practice Question
A SaaS application allows users to upload profile pictures. The development team wants to prevent upload of malicious files that could compromise the server. Which control is most effective?
⚠ Common exam trap
CCSP often tests the misconception that restricting file extensions or MIME types is sufficient upload protection, when the real control must inspect file content because extensions and headers are attacker-controlled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement server-side antivirus scanning on all uploaded files before saving.
Server-side antivirus scanning inspects the actual file content after upload and before it is persisted or served, which is the only control here that detects malicious payloads regardless of file type or extension. It catches malware embedded in files that pass superficial checks, including polyglot files and weaponized images. Because scanning happens on the server, attackers cannot bypass it by manipulating client-side validation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store files in a CDN that only serves static content.
Why it's wrong here
A CDN serves content after upload; it does not inspect or reject the file during ingestion, so a malicious payload still reaches origin storage. CDNs suit caching and delivery of static assets at scale. Preventing server compromise requires validating the file's actual content before it is stored.
- ✗
Set a maximum file size limit to 2 MB.
Why it's wrong here
A size limit only bounds resource consumption; a small malicious script or polyglot image well under 2 MB still executes if later interpreted. Size caps suit denial-of-service and storage-abuse mitigation. They do not verify file type or content, so server compromise remains possible.
- ✓
Implement server-side antivirus scanning on all uploaded files before saving.
Why this is correct
Server-side scanning intercepts every upload before it reaches storage, catching malware the client cannot be trusted to detect. This directly satisfies the stem's constraint of preventing malicious files from compromising the server, since client-side checks are bypassable and signature-only filtering misses embedded payloads.
- ✗
Restrict file uploads to only image file types by checking the file extension.
Why it's wrong here
Extension checking is trivially bypassed by renaming a malicious file, and it inspects only the filename, not the bytes. It suits basic user-experience filtering, not security. Effective prevention requires content-based validation such as magic-byte inspection and re-encoding of the image.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.