Courseiva

CCSP Server-Side Request Forgery (SSRF) Practice Question

A security engineer is investigating an incident where an attacker exploited a server-side request forgery (SSRF) vulnerability in a cloud application. The application runs in a cloud environment and uses internal metadata endpoints. Which mitigation should be prioritized to prevent future SSRF attacks?

⚠ Common exam trap

ISC2 often tests the misconception that input validation or WAFs are sufficient to stop SSRF, when in reality the most effective mitigation is network-layer egress filtering that blocks access to internal metadata endpoints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict outbound network access from the application instances using network security controls

Restricting outbound network access from application instances using security groups directly prevents the application from reaching internal metadata endpoints and other internal services. This is a fundamental network-layer control that stops SSRF attacks at the source, regardless of input validation or request inspection, by blocking the outbound traffic that the attacker would exploit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement input validation to block malicious URLs

    Why it's wrong here

    Input validation cannot reliably block SSRF because attackers encode, redirect or obfuscate URLs past filters, and the cloud metadata endpoint (169.254.169.254) is a legitimate address that validation may permit. It is tempting because validation is standard for injection flaws, and would suit blocking known-bad external URL patterns.

  • ✓

    Restrict outbound network access from the application instances using network security controls

    Why this is correct

    SSRF abuses the application's ability to make outbound requests, so restricting egress with network security controls prevents instances from reaching internal metadata endpoints such as 169.254.169.254. This directly addresses the cloud metadata exposure described in the stem.

  • ✗

    Deploy a web application firewall (WAF) to inspect outgoing requests

    Why it's wrong here

    A WAF inspects inbound HTTP traffic, not the outbound requests the application server makes after parsing the URL, so SSRF to the metadata endpoint passes through. It is tempting because WAFs are the usual control for web-layer attacks, and would be correct for filtering inbound request payloads against known signatures.

  • ✗

    Require token-based authentication for metadata service access

    Why it's wrong here

    Token-based authentication is not a control the application can impose on the cloud metadata service; the instance endpoint is reachable without credentials from the workload, so requiring tokens is not enforceable here. It is tempting because token auth secures API access, and would be correct for protecting a custom internal API.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.