CCSP Cloud Platform and Infrastructure Security Practice Question
A security analyst is configuring an API Gateway for a cloud application. The application must handle high traffic and prevent abuse from a single client. Which feature should the analyst enable to limit the number of requests from a client within a specified time window?
⚠ Common exam trap
The trap is confusing authentication (API keys) or encryption (TLS) with abuse prevention — candidates may think that requiring an API key stops abuse, but the exam tests whether you know that only rate limiting enforces request quotas per client.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rate limiting
Rate limiting is the API Gateway feature that restricts the number of requests a client can make within a specified time window (e.g., 1000 requests per minute). It directly addresses the requirement to handle high traffic and prevent abuse from a single client by throttling or rejecting excess requests. This protects backend services from being overwhelmed and ensures fair usage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Rate limiting
Why this is correct
Rate limiting caps the number of requests a client may send within a defined time window, returning throttling responses once the threshold is exceeded. This directly satisfies the requirement to prevent a single client from abusing the API during high traffic.
- ✗
TLS enforcement
Why it's wrong here
TLS enforcement encrypts data in transit between client and gateway; it does not count or cap requests, so a single client can still flood the API. It is tempting because it is a core API Gateway security setting, and it would be correct when the requirement is to enforce HTTPS-only connections and reject plaintext HTTP traffic.
- ✗
Web Application Firewall (WAF) integration
Why it's wrong here
WAF protects against web exploits, not rate-based abuse.
- ✗
API key authentication
Why it's wrong here
API key authentication identifies and authorises callers but imposes no request ceiling, so a single client can still overwhelm the gateway. It is tempting because API keys are a standard gateway feature for controlling access, and they would be correct when the requirement is to authenticate and track which client is calling the API.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.