hardMultiple Choice
CCSP Practice Question: An attacker exploits a cloud application to make…
An attacker exploits a cloud application to make HTTP requests to an internal metadata service and retrieve temporary credentials. Which control would be most effective in preventing this attack?
⚠ Common exam trap
ISC2 often tests the distinction between inbound controls (WAF, input validation) and outbound controls (egress filtering) for SSRF attacks, and the trap here is that candidates assume a WAF or input validation can block internal requests when only network-layer egress rules can stop the outbound connection to the metadata service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network-level egress filtering to block 169.254.169.254
The attack exploits the cloud metadata service at the link-local address 169.254.169.254 (RFC 3927). Network-level egress filtering blocks outbound traffic to this IP, preventing the attacker from reaching the metadata service even if the application is compromised. This is a fundamental defense-in-depth control for cloud workloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using signed URLs for all requests
Why it's wrong here
Signed URLs authenticate access to storage objects; they do not restrict the application server from reaching the metadata endpoint, so the SSRF still succeeds. It is tempting because signing protects object access, and it would be correct for granting time-limited access to specific cloud storage resources.
- ✗
Web Application Firewall (WAF) rules
Why it's wrong here
WAF rules inspect inbound traffic, not the outbound request the application makes to the link-local metadata address, so the credential theft proceeds. It is tempting because WAFs block many web exploits, and it would be correct for filtering inbound HTTP attacks against the application.
- ✓
Network-level egress filtering to block 169.254.169.254
Why this is correct
SSRF to the instance metadata service requires the workload to reach the link-local address 169.254.169.254. Blocking that destination at the network egress layer prevents credential retrieval even if the application is exploited, satisfying the containment constraint.
- ✗
Input validation on URL parameters
Why it's wrong here
Validating URL parameters cannot stop server-side request forgery, because the application itself issues the request to the metadata endpoint after validation passes. It is tempting as a general injection defence, and it would be correct for blocking malformed or malicious input in form fields and query strings.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.