Courseiva

CCSP Cloud Application Security Practice Question

A security analyst is reviewing application logs and notices that a large number of requests from a single IP address are attempting to access a REST API endpoint with invalid session tokens. Which cloud-based mitigation is MOST effective at blocking such automated attacks?

⚠ Common exam trap

Watch out — candidates often confuse session token management (e.g., rotation, encryption) with the need for a perimeter defense that controls request volume and source, leading them to pick options that address token validity rather than the automated, high-volume nature of the attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a web application firewall (WAF) with rate limiting and IP blacklisting

A Web Application Firewall (WAF) with rate limiting and IP blacklisting directly addresses the described attack: a single IP flooding a REST API with invalid session tokens. Rate limiting throttles the number of requests from that IP, while IP blacklisting blocks it entirely, preventing automated brute-force or credential-stuffing attempts at the cloud edge before they reach the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rotate API keys more frequently

    Why it's wrong here

    Rotating API keys changes credentials on a schedule; it does nothing to block requests already arriving with invalid session tokens from one IP address. Rotation is tempting because it limits exposure after credential compromise. Rate limiting or a WAF rule blocking that source addresses the automated attack pattern directly.

  • ✗

    Implement cross-origin resource sharing (CORS) policies

    Why it's wrong here

    CORS policies govern which browser origins may read responses; they do not block server-side or scripted requests carrying invalid session tokens. CORS is tempting because it hardens browser-facing APIs against cross-origin abuse. A WAF rate-based rule or IP block targets the automated request flood itself.

  • ✓

    Configure a web application firewall (WAF) with rate limiting and IP blacklisting

    Why this is correct

    A WAF inspects HTTP traffic and applies rate limiting plus IP blacklisting, throttling or dropping the abusive source before requests reach the API. This blocks automated token-guessing floods more effectively than host-level or identity controls.

  • ✗

    Require encryption of session tokens

    Why it's wrong here

    Encrypting session tokens protects them in transit and at rest, but the attacker is already sending invalid tokens, so encryption changes nothing about the request volume. Encryption is tempting as general API hardening. A WAF rate-limiting rule or IP reputation block stops the automated flood.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.