Courseiva
hardMultiple Choice

CCSP Practice Question: An attacker exploits a cloud application to make…

An attacker exploits a cloud application to make HTTP requests to an internal metadata service and retrieve temporary credentials. Which control would be most effective in preventing this attack?

⚠ Common exam trap

ISC2 often tests the distinction between inbound controls (WAF, input validation) and outbound controls (egress filtering) for SSRF attacks, and the trap here is that candidates assume a WAF or input validation can block internal requests when only network-layer egress rules can stop the outbound connection to the metadata service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network-level egress filtering to block 169.254.169.254

The attack exploits the cloud metadata service at the link-local address 169.254.169.254 (RFC 3927). Network-level egress filtering blocks outbound traffic to this IP, preventing the attacker from reaching the metadata service even if the application is compromised. This is a fundamental defense-in-depth control for cloud workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using signed URLs for all requests

    Why it's wrong here

    Signed URLs authenticate access to storage objects; they do not restrict the application server from reaching the metadata endpoint, so the SSRF still succeeds. It is tempting because signing protects object access, and it would be correct for granting time-limited access to specific cloud storage resources.

  • ✗

    Web Application Firewall (WAF) rules

    Why it's wrong here

    WAF rules inspect inbound traffic, not the outbound request the application makes to the link-local metadata address, so the credential theft proceeds. It is tempting because WAFs block many web exploits, and it would be correct for filtering inbound HTTP attacks against the application.

  • ✓

    Network-level egress filtering to block 169.254.169.254

    Why this is correct

    SSRF to the instance metadata service requires the workload to reach the link-local address 169.254.169.254. Blocking that destination at the network egress layer prevents credential retrieval even if the application is exploited, satisfying the containment constraint.

  • ✗

    Input validation on URL parameters

    Why it's wrong here

    Validating URL parameters cannot stop server-side request forgery, because the application itself issues the request to the metadata endpoint after validation passes. It is tempting as a general injection defence, and it would be correct for blocking malformed or malicious input in form fields and query strings.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.