Courseiva

CCNA Cloud App Security Questions

75 of 114 questions · Page 1/2 · Cloud App Security topic · Answers revealed

1
MCQhard

A security engineer is reviewing a cloud application that uses OAuth 2.0 to delegate access to a third-party API. The application is a single-page application (SPA) running in the browser. The engineer wants to prevent authorization code interception and ensure that the client cannot impersonate another client. Which OAuth 2.0 enhancement should be implemented?

A.Proof Key for Code Exchange (PKCE)
B.OpenID Connect (OIDC) with the implicit flow
C.Client credentials grant with a client secret
D.Resource owner password credentials grant
AnswerA

PKCE mitigates authorization code interception attacks by requiring the client to send a code verifier that matches a previously sent code challenge. This binds the authorization code to the client that initiated the request, preventing an attacker who intercepts the code from exchanging it. For SPAs, which cannot securely store client secrets, PKCE is the recommended enhancement.

Why this answer

PKCE is specifically designed to secure the authorization code flow for public clients like SPAs that cannot hold a client secret. It prevents code interception by binding the code to a dynamically generated verifier. The implicit flow, client credentials, and resource owner password credentials either expose tokens or require secrets that SPAs cannot protect, and none address code interception.

Exam trap

The trap here is assuming that OIDC or the implicit flow solves SPA security, when PKCE is the required enhancement for the authorization code flow in public clients.

2
Multi-Selectmedium

Which TWO are effective strategies for securing cloud application data at rest?

Select 2 answers
A.Role-based access control
B.Database activity monitoring
C.File-level encryption
D.Transparent data encryption
E.Network segmentation
AnswersC, D

File-level encryption protects data at rest per file or object, so each item carries its own cryptographic boundary independent of the storage volume. This satisfies the stem's at-rest requirement by securing data even when underlying storage, snapshots or backups are exposed, unlike volume-level controls.

Why this answer

File-level encryption (C) is correct because it encrypts individual files or folders on disk, ensuring that data at rest remains unreadable even if the underlying storage or host is compromised. Transparent data encryption (D) is correct because it encrypts database files and backups at rest at the storage engine level, protecting data without requiring application changes. Both directly address the confidentiality of stored data, which is the core goal of securing data at rest.

Role-based access control (A) governs who may access resources but does not itself encrypt stored data. Database activity monitoring (B) detects and alerts on suspicious database activity but is a detective control, not a data-at-rest protection. Network segmentation (E) limits lateral movement and exposure but does not protect data at rest on storage media.

Exam trap

ISC2 often tests the distinction between access control (RBAC) and encryption, where candidates mistakenly think that restricting access is sufficient to secure data at rest, ignoring that encryption is required to protect against physical theft or unauthorized storage-level access.

3
MCQhard

A cloud-native application uses a microservices architecture deployed on Kubernetes. The security team wants to ensure that only authorized services can communicate with each other, and that communication is encrypted. Which Kubernetes feature should be used to meet these requirements?

A.Role-Based Access Control (RBAC) to restrict which services can access the Kubernetes API.
B.Kubernetes Secrets to store service credentials and TLS certificates.
C.Pod Security Policies to enforce security contexts and prevent privileged containers.
D.Network Policies with a service mesh like Istio for mutual TLS.
AnswerD

Network Policies control pod-to-pod communication at Layer 3/4, but they do not encrypt traffic. A service mesh like Istio provides mutual TLS (mTLS) for service-to-service encryption and can enforce authorization policies. Together, they ensure only authorized services communicate and that traffic is encrypted, meeting both requirements.

Why this answer

Network Policies provide segmentation by allowing or denying traffic between pods based on labels and namespaces. However, they do not encrypt traffic. A service mesh like Istio adds mutual TLS (mTLS) to encrypt all service-to-service communication and can enforce fine-grained authorization policies.

Using both together ensures that only authorized services communicate and that the traffic is encrypted.

Exam trap

The trap here is assuming that Network Policies alone provide encryption, or that RBAC or Secrets can secure service communication, when they address different layers.

4
Multi-Selecthard

Which TWO of the following are effective methods to protect against server-side request forgery (SSRF) in a cloud application? (Choose two.)

Select 2 answers
A.Use SSL inspection to check for malicious payloads
B.Whitelist allowed outbound destinations
C.Block all outbound network traffic from the application
D.Disable unused URL schemes such as file:// and dict://
E.Sanitize all user input for URL parameters
AnswersB, D

Whitelisting prevents requests to internal or malicious hosts.

Why this answer

Whitelisting allowed outbound destinations is a primary defense against SSRF. By explicitly permitting only trusted external hosts (e.g., specific API endpoints or internal services), the application cannot be tricked into making requests to arbitrary internal or external targets, even if an attacker controls the URL parameter.

Exam trap

ISC2 often tests the misconception that input sanitization alone is sufficient for SSRF protection, when in reality the attack exploits the server's trust in the destination, not the input format, making whitelisting and scheme restrictions the effective controls.

5
MCQmedium

A cloud application experiences intermittent failures during peak load. Logs show database connection timeouts. Which architecture change would best address this issue?

A.Implement connection pooling
B.Enable auto-scaling on the application tier
C.Use read replicas
D.Increase database instance size
AnswerA

Connection pooling reuses established database connections instead of opening a new one per request, so the application stops exhausting the database's connection limit during peak load. This directly removes the connection-timeout constraint recorded in the logs, letting concurrent requests queue briefly rather than fail outright.

Why this answer

Connection pooling reuses a set of established database connections, avoiding the overhead of repeatedly opening and closing connections during high concurrency. This directly resolves intermittent timeouts caused by connection exhaustion or slow connection establishment under peak load, without requiring additional infrastructure.

Exam trap

ISC2 often tests the misconception that scaling the application tier or database size alone solves connection management issues, when the real bottleneck is connection establishment overhead and pool limits.

How to eliminate wrong answers

Option B is wrong because auto-scaling the application tier adds more compute instances, which increases the number of concurrent database connection requests and can worsen connection exhaustion, not fix it. Option C is wrong because read replicas only offload read queries, not the connection management overhead or write-related timeouts. Option D is wrong because increasing database instance size provides more memory/CPU but does not address the fundamental issue of connection churn or exhaustion; the database may still hit its max_connections limit.

6
MCQhard

A cloud application uses a microservices architecture deployed on Kubernetes. The security team wants to enforce that only signed container images from a trusted registry can be deployed to the cluster. Which Kubernetes feature should be used to achieve this?

A.Pod security policies
B.Role-based access control (RBAC)
C.Admission controllers with image signature verification
D.Network policies
AnswerC

Admission controllers intercept requests to the Kubernetes API server before objects are persisted. By integrating an admission controller that verifies image signatures, such as the Open Policy Agent (OPA) Gatekeeper with a signature verification policy or the Sigstore policy controller, you can enforce that only images signed by trusted keys are admitted. This directly meets the requirement to allow only signed images from a trusted registry.

Why this answer

To enforce that only signed container images from a trusted registry are deployed, an admission controller with image signature verification is required. This controller validates the signature of the image before allowing the pod to be created. Tools like OPA Gatekeeper or Sigstore's policy controller can be configured to check signatures against trusted public keys.

This ensures supply chain security and prevents unauthorized or tampered images from running in the cluster.

Exam trap

The trap here is confusing access control (RBAC) or network segmentation (Network policies) with image integrity enforcement, which requires an admission controller that can verify cryptographic signatures.

7
Multi-Selectmedium

A company is building a cloud-native API that uses OAuth 2.0 for delegated authorization. The security team wants to harden the authorization code flow against token interception and misuse. Which two measures should be implemented to protect the authorization code and tokens? (Choose two.)

Select 2 answers
A.Enable PKCE so the client sends a code challenge and later proves possession of the corresponding verifier when exchanging the code.
B.Require the authorization server to issue the authorization code with a short lifetime and bind it to the client identifier and redirect URI.
C.Store refresh tokens in browser local storage to allow the client to silently renew access tokens without user interaction.
D.Configure the resource server to accept access tokens in query string parameters so that clients can easily include them in requests.
E.Use the implicit grant so that tokens are returned directly from the authorization endpoint without an intermediate code.
AnswersA, B

PKCE binds the authorization code to the client that initiated the request by requiring a verifier that matches the earlier challenge. An attacker who intercepts the code cannot redeem it without the verifier, which is never sent through the browser redirect. This directly mitigates authorization code interception, especially for public clients, and is a recommended hardening measure.

Why this answer

Hardening the authorization code flow focuses on preventing intercepted codes from being redeemed by an attacker. Binding the code to the client and redirect URI, combined with a short lifetime, limits replay. PKCE adds proof of possession so a stolen code is useless without the verifier.

Together they address interception and misuse without exposing tokens to the browser or weakening transport protections.

Exam trap

The trap here is confusing the implicit grant or query-string tokens as simplifications that improve security, when both actually increase token exposure.

8
MCQhard

A cloud-native SaaS provider uses OpenID Connect (OIDC) for user authentication. The security architect wants to reduce the impact of stolen authorization codes and ensure that tokens issued to a single-page application cannot be replayed by a different client. Which OIDC mechanism should be implemented?

A.Configure the authorization server to use the implicit flow so that no authorization code is ever issued.
B.Require the authorization server to issue sender-constrained access tokens using Demonstrating Proof of Possession (DPoP).
C.Use PKCE with the S256 code challenge method and validate the redirect URI against a registered value.
D.Enable refresh token rotation and bind refresh tokens to the client's IP address.
AnswerC

PKCE binds the authorization code to the client that initiated the request by requiring the code verifier at token exchange, preventing a different client from redeeming a stolen code. Combined with strict redirect URI validation, it protects public clients such as SPAs. This directly addresses code interception and client binding, which are the stated concerns.

Why this answer

PKCE with S256 ties the authorization code to the initiating client via the code verifier, so a stolen code cannot be redeemed by an attacker who does not possess the verifier. Strict redirect URI validation further constrains where codes and tokens can be delivered. Together they directly mitigate code interception and cross-client replay for public clients like SPAs.

Exam trap

The trap here is confusing token replay mitigations such as DPoP with authorization code protection, when the scenario specifically targets stolen codes and client binding.

9
MCQmedium

A healthcare SaaS provider is deploying a new application that processes protected health information (PHI). The application uses a microservices architecture running on Kubernetes. Each microservice stores its data in a separate database. The compliance team requires that all data at rest be encrypted and that encryption keys be managed by the customer (CMEK). The cloud provider supports KMS with CMEK. However, the development team wants to use a single customer-managed key for all databases to simplify key management. The security architect is concerned about the blast radius if the key is compromised. Which of the following recommendations best balances security and operational efficiency?

A.Use the cloud provider's default encryption keys for all databases
B.Use a separate customer-managed key for each database, with automated key rotation
C.Disable encryption to improve performance and use network segmentation instead
D.Use one customer-managed key for all databases, but enable automatic key rotation
AnswerB

Per-database customer-managed keys contain the blast radius: compromising one key exposes only that microservice's data, satisfying the architect's isolation concern. Automated rotation limits exposure windows without manual overhead, preserving the operational efficiency the single-key approach sought. This balances both constraints better than one shared key.

Why this answer

It minimizes the blast radius by ensuring that compromise of one key does not expose data in other databases, while automated key rotation reduces the window of vulnerability and operational overhead. This aligns with the principle of least privilege and the compliance requirement for customer-managed encryption keys (CMEK). Using separate keys per database is a standard security best practice for microservices architectures, especially when handling PHI.

Exam trap

ISC2 often tests the tension between operational simplicity and security blast radius, where candidates may choose a single key with rotation (Option D) thinking it balances both, but fail to recognize that rotation does not shrink the blast radius of a compromised key that has already been used to encrypt data.

How to eliminate wrong answers

Option A is wrong because using the cloud provider's default encryption keys violates the compliance requirement that encryption keys be managed by the customer (CMEK), and it does not allow the customer to control key lifecycle or rotation. Option C is wrong because disabling encryption for PHI at rest is a direct violation of compliance mandates (e.g., HIPAA) and security best practices; network segmentation alone does not protect data at rest. Option D is wrong because using a single customer-managed key for all databases creates a single point of failure and a large blast radius—if that key is compromised, all databases are exposed, and automatic rotation does not mitigate the risk of a key already being compromised.

10
MCQmedium

A cloud security engineer is reviewing the authentication mechanism for a web application. The application currently uses API keys transmitted in the URL query string. What is the primary security concern with this approach?

A.API keys in URLs are often logged in plaintext in server logs and browser history.
B.API keys in query strings are not encrypted, even with HTTPS.
C.API keys provide weak authentication because they are not tied to a user session.
D.API keys are not valid for use in query strings; they require a certificate.
AnswerA

Query strings are captured verbatim by web servers, proxies and browsers, so the key lands in access logs and history in cleartext. Anyone with log or shared-device access replays it. This directly satisfies the stem's concern about the transmission location of the credential.

Why this answer

The primary security concern with transmitting API keys in URL query strings is that URLs are frequently logged in plaintext by web servers, proxies, and browsers. This means the API key can be inadvertently exposed in server access logs, browser history, and referrer headers, making it accessible to anyone with access to those logs. Even with HTTPS encrypting the data in transit, the URL itself is often logged before decryption or after encryption at the termination point, so the key remains visible in log files.

Exam trap

ISC2 often tests the misconception that HTTPS fully protects the URL from all exposure, but the trap here is that while HTTPS encrypts data in transit, it does not prevent logging, caching, or referrer leakage of the URL.

How to eliminate wrong answers

Option B is wrong because HTTPS does encrypt the entire HTTP request, including the query string, during transit; the issue is not lack of encryption on the wire but exposure in logs and history. Option C is wrong because API keys are a valid authentication method and can be tied to a user session or application identity; the weakness here is not about session binding but about exposure in URLs. Option D is wrong because API keys are valid for use in query strings; they do not require a certificate, and certificates are used for TLS mutual authentication, not for API key transmission.

11
Multi-Selecteasy

A security team is reviewing controls for a cloud application that transmits personally identifiable information (PII) over the internet. Which TWO controls are essential for protecting data in transit?

Select 2 answers
A.Use of signed certificates from a trusted CA
B.Regular penetration testing
C.Implementation of IPsec VPNs
D.Use of TLS 1.2 or higher
E.Encryption at rest using AES-256
AnswersA, D

Signed certificates from a trusted certificate authority let the client verify the server's identity during the TLS handshake, preventing man-in-the-middle interception of PII in transit. Without this authentication, encryption alone cannot confirm the endpoint, so it satisfies the stem's essential control for protecting data in transit.

Why this answer

Option A is correct because signed certificates from a trusted Certificate Authority authenticate the server's identity and enable the client to establish a trusted TLS session, preventing man-in-the-middle attacks on PII in transit. Option D is correct because TLS 1.2 or higher provides strong, modern cryptographic protection (e.g., AES-GCM, ECDHE key exchange) for data transmitted over untrusted networks like the internet. Together, these controls directly secure data in transit by ensuring both endpoint authenticity and encryption.

Option B (penetration testing) is a validation activity, not a protective in-transit control. Option C (IPsec VPNs) can encrypt traffic but is not essential for a cloud application exposed to arbitrary internet clients, where TLS is the appropriate mechanism. Option E (AES-256 at rest) protects stored data, not data in transit.

Exam trap

ISC2 often tests the distinction between 'essential' controls for data in transit versus 'helpful' or 'related' controls, so candidates mistakenly pick IPsec VPNs (Option C) because they associate VPNs with secure transmission, even though TLS is the standard and essential control for web-based cloud applications.

12
MCQhard

A SaaS provider uses a customer-managed encryption key (CMEK) model for data-at-rest. The provider's application runs in a multi-tenant cloud environment. Which attack surface is MOST directly mitigated by this approach?

A.Misconfigured storage buckets exposing data
B.Insider threats from cloud provider employees
C.SQL injection vulnerabilities in the application
D.Side-channel attacks on shared physical hardware
AnswerB

CMEK prevents provider access to customer data without the key.

Why this answer

A customer-managed encryption key (CMEK) model gives the customer control over the key used to encrypt data at rest. This directly mitigates the risk of a cloud provider employee accessing the plaintext data, because even if the employee has administrative access to the storage infrastructure, they cannot decrypt the data without the customer's key. The provider holds the encrypted data, but the decryption key is managed and controlled by the customer, creating a logical separation that protects against insider threats from the provider's personnel.

Exam trap

ISC2 often tests the misconception that encryption alone prevents all data exposure, but the trap here is that candidates confuse data-at-rest encryption with access control or application security, failing to recognize that CMEK specifically addresses the insider threat from the cloud provider's staff who might otherwise access raw storage.

How to eliminate wrong answers

Option A is wrong because misconfigured storage buckets expose data through incorrect access control policies (e.g., public read/write ACLs), which encryption does not prevent—encryption protects data at rest but does not enforce access controls. Option C is wrong because SQL injection is an application-layer attack that exploits improper input validation in the application code, and encryption of data at rest does not prevent injection or protect data while it is being processed in memory. Option D is wrong because side-channel attacks on shared physical hardware exploit timing, power consumption, or electromagnetic leaks to infer data; encryption keys managed by the customer do not prevent these physical-layer attacks, which target the compute or memory operations rather than the stored encrypted data.

13
MCQmedium

A security architect is designing access controls for a cloud-based microservices application. Which approach best aligns with the principle of least privilege for service-to-service authentication?

A.Use long-lived bearer tokens
B.Implement mutual TLS with unique certificates per service
C.Assign IAM roles with broad permissions
D.Use a shared API key across all services
AnswerB

Mutual TLS authenticates both ends using distinct per-service certificates, so each microservice proves its identity and only trusted peers connect. This enforces least privilege for service-to-service authentication rather than relying on shared secrets or network location.

Why this answer

Mutual TLS (mTLS) with unique certificates per service enforces least privilege by ensuring each microservice authenticates with a distinct identity, and access can be scoped to specific certificates. This prevents a compromised service from impersonating others, as each service has its own private key and certificate, and the TLS handshake requires both sides to present and validate certificates.

Exam trap

ISC2 often tests the misconception that shared secrets or broad IAM roles are acceptable for service-to-service communication, but the trap is that candidates overlook the need for per-service identity and cryptographic proof of identity, which mTLS uniquely provides.

How to eliminate wrong answers

Option A is wrong because long-lived bearer tokens, such as static OAuth2 tokens, increase the risk of token theft and reuse; they lack the per-request cryptographic binding of mTLS and violate least privilege by providing persistent access without rotation. Option C is wrong because assigning IAM roles with broad permissions (e.g., wildcard actions or resources) grants excessive privileges, directly contradicting the principle of least privilege by allowing a service to access more than necessary. Option D is wrong because a shared API key across all services creates a single point of failure and common credential; if the key is compromised, all services are exposed, and there is no way to isolate or revoke access per service.

14
MCQhard

A cloud application team is designing a multi-tenant SaaS platform on a public cloud. Tenant data is stored in a shared database, and the application uses a single service account to connect. During a threat modeling session, the security architect raises concerns that a coding error could allow one tenant to read another tenant's records. Which control should be implemented to provide defense in depth against this cross-tenant data access risk?

A.Create a separate database schema for each tenant and grant the application service account access only to the schema corresponding to the current request.
B.Enforce row-level security policies in the database that filter queries based on a tenant identifier derived from the authenticated session context.
C.Encrypt each tenant's data with a separate customer-managed key and store the key identifier in the application configuration.
D.Implement a Web Application Firewall rule that inspects request parameters for tenant identifiers and blocks requests where the identifier does not match the authenticated user.
AnswerB

Row-level security in the database enforces tenant isolation at the data layer, so even if application code omits a tenant filter, the database restricts rows to the current tenant. Deriving the tenant identifier from the authenticated session context ties the policy to identity rather than trusting application-supplied values. This provides defense in depth against coding errors that could otherwise expose cross-tenant data.

Why this answer

Row-level security enforces tenant boundaries inside the database engine, independent of application query construction. By deriving the tenant identifier from the authenticated session, the policy cannot be bypassed by a forgotten WHERE clause or a manipulated parameter. This creates a reliable second layer of defense that complements application-level checks and encryption, directly mitigating the cross-tenant read risk identified during threat modeling.

Exam trap

The trap here is treating encryption or a WAF as sufficient tenant isolation, when only database-enforced row filtering prevents a coding error from returning another tenant's rows.

15
MCQeasy

Refer to the exhibit. A log entry shows a suspected SQL injection attack. Which security control would have prevented this attack?

A.Encrypt the database connection
B.Implement rate limiting on the login endpoint
C.Enforce strong password policies
D.Use parameterized SQL queries
AnswerD

Parameterised queries bind user input as data rather than concatenating it into SQL text, so injected syntax never becomes executable code. This eliminates the injection vector at source, which no signature or input-filtering control achieves as reliably.

Why this answer

SQL injection attacks exploit unsanitized user input that is concatenated into SQL queries. Parameterized queries (also known as prepared statements) separate SQL logic from data by using placeholders, ensuring that user input is always treated as data, not executable code. This prevents an attacker from injecting malicious SQL commands, regardless of the input content.

Exam trap

ISC2 often tests the distinction between network-layer controls (like encryption) and application-layer controls (like input validation), and the trap here is that candidates confuse encryption of the connection with prevention of injection, thinking encrypted traffic cannot carry malicious payloads.

How to eliminate wrong answers

Option A is wrong because encrypting the database connection (e.g., using TLS/SSL) protects data in transit from eavesdropping but does not prevent the execution of malicious SQL statements; the injection still occurs at the application layer. Option B is wrong because rate limiting on the login endpoint only mitigates brute-force or credential-stuffing attacks by restricting request frequency; it has no effect on the content of a single request that contains SQL injection payload. Option C is wrong because enforcing strong password policies (e.g., complexity, length) reduces the risk of credential compromise but does not address the vulnerability of unsanitized input in SQL queries; an attacker can still inject SQL without needing valid credentials.

16
MCQeasy

A developer wants to ensure that sensitive data in a cloud database is protected even if the database backup files are stolen. Which best practice should be implemented?

A.Restrict access to the backup files using IAM roles.
B.Use a virtual private cloud (VPC) to isolate the database from the internet.
C.Enable transparent data encryption (TDE) with customer-managed keys for the database and its backups.
D.Implement data tokenization for all sensitive fields.
AnswerC

TDE encrypts database files and their backups at rest, so stolen backup media yields only ciphertext. Customer-managed keys keep control of decryption outside the provider, satisfying the requirement that sensitive data stays protected even when backup files are exfiltrated.

Why this answer

Transparent Data Encryption (TDE) with customer-managed keys encrypts the database at rest and, when properly configured, also encrypts backup files. This ensures that even if backup files are stolen, the data remains unreadable without the decryption keys, providing a strong defense against data breaches involving physical or logical theft of backups.

Exam trap

The trap here is that candidates often confuse network-level controls (VPC isolation) or access controls (IAM) with data-at-rest encryption, failing to recognize that backup files are a separate attack surface requiring encryption specifically applied to the backup media.

How to eliminate wrong answers

Option A is wrong because restricting access with IAM roles protects against unauthorized access to the backup files but does not encrypt the data within them; if the files are stolen (e.g., via physical theft or a compromised storage layer), the data is still readable. Option B is wrong because using a VPC isolates the database from the internet but does not encrypt backup files; a VPC controls network traffic, not data at rest, so stolen backups remain unprotected. Option D is wrong because data tokenization replaces sensitive data with tokens, but it requires an external tokenization service and does not inherently protect backup files; if the token mapping is compromised or the backup contains tokens, the original data may still be exposed, and tokenization is not a direct backup encryption mechanism.

17
MCQmedium

A SaaS application allows users to upload profile pictures. The development team wants to prevent upload of malicious files that could compromise the server. Which control is most effective?

A.Store files in a CDN that only serves static content.
B.Set a maximum file size limit to 2 MB.
C.Implement server-side antivirus scanning on all uploaded files before saving.
D.Restrict file uploads to only image file types by checking the file extension.
AnswerC

Server-side scanning intercepts every upload before it reaches storage, catching malware the client cannot be trusted to detect. This directly satisfies the stem's constraint of preventing malicious files from compromising the server, since client-side checks are bypassable and signature-only filtering misses embedded payloads.

Why this answer

Server-side antivirus scanning inspects the actual file content after upload and before it is persisted or served, which is the only control here that detects malicious payloads regardless of file type or extension. It catches malware embedded in files that pass superficial checks, including polyglot files and weaponized images. Because scanning happens on the server, attackers cannot bypass it by manipulating client-side validation.

Exam trap

CCSP often tests the misconception that restricting file extensions or MIME types is sufficient upload protection, when the real control must inspect file content because extensions and headers are attacker-controlled.

How to eliminate wrong answers

Option A is wrong because a CDN serving static content only limits execution context — it does not detect or remove malicious files, and a stored malicious file can still be downloaded and executed by victims. Option B is wrong because a 2 MB size limit only mitigates denial-of-service or storage abuse; a 50 KB web shell or malware-laden image is unaffected. Option D is wrong because checking the file extension is trivially bypassed by renaming a .exe or .php to .jpg, and even magic-byte checks can be defeated with polyglot files — extension validation is not content inspection.

18
MCQhard

An organization uses a CI/CD pipeline that automatically builds and deploys container images to a Kubernetes cluster. A security scanner flags that the base image contains a critical vulnerability. What is the best course of action to prevent vulnerable images from being deployed?

A.Replace the base image with a minimal image like Alpine.
B.Manually review and patch the base image before each build.
C.Integrate a container image scanning tool into the CI/CD pipeline that blocks builds if critical vulnerabilities are found.
D.Configure the scanner to send alerts after deployment.
AnswerC

Embedding scanning directly in the pipeline enforces a fail-closed gate: the build job inspects the image layers and aborts before the artefact reaches the cluster, satisfying the requirement to prevent vulnerable images from being deployed rather than merely detecting them post-deployment.

Why this answer

Integrating a container image scanning tool directly into the CI/CD pipeline and configuring it to block the build when critical vulnerabilities are found ensures that vulnerable images never reach the Kubernetes cluster. This shift-left approach enforces security gates automatically, preventing deployment of non-compliant images without relying on manual intervention or post-deployment alerts.

Exam trap

The trap here is that candidates may think replacing the base image with a minimal one (Option A) is sufficient, but ISC2 often tests that security must be automated and enforced as a gate in the pipeline, not just a manual or reactive measure.

How to eliminate wrong answers

Option A is wrong because simply replacing the base image with a minimal image like Alpine does not guarantee the absence of critical vulnerabilities; Alpine images can also contain vulnerabilities, and the approach does not address the need for automated scanning and blocking in the pipeline. Option B is wrong because manually reviewing and patching the base image before each build is not scalable, error-prone, and contradicts the automation principles of CI/CD; it also introduces delays and does not prevent human oversight. Option D is wrong because configuring the scanner to send alerts after deployment allows vulnerable images to be deployed into production, which defeats the purpose of preventing vulnerable images from being deployed; alerts after the fact do not block the deployment.

19
MCQhard

An organization deploys a serverless application using AWS Lambda functions that access an RDS database. Which practice best ensures that the database credentials are protected?

A.Store credentials in the function code
B.Use AWS Systems Manager Parameter Store with KMS encryption and IAM roles
C.Hardcode credentials in environment variables
D.Use database temporary tokens generated on the fly
AnswerB

Storing credentials in Systems Manager Parameter Store with KMS encryption keeps secrets encrypted at rest, while IAM roles let Lambda retrieve them without embedded static keys. This satisfies the scenario's constraint of protecting database credentials in a serverless environment, since no long-lived secrets reside in function code or environment variables.

Why this answer

AWS Systems Manager Parameter Store, combined with AWS KMS for encryption and IAM roles for access control, provides a secure, auditable, and managed way to store and retrieve database credentials. This approach avoids embedding secrets in code or environment variables, and it integrates natively with AWS Lambda via the IAM execution role, ensuring that only authorized functions can decrypt and access the credentials.

Exam trap

The trap here is that candidates often confuse 'temporary tokens' (Option D) with a secure credential storage method, but the CCSP exam expects you to recognize that managing the initial secret (the token's root of trust) is still required, and Parameter Store with KMS is the definitive best practice for protecting static credentials in serverless architectures.

How to eliminate wrong answers

Option A is wrong because storing credentials directly in the function code exposes them to anyone with read access to the code repository or deployment artifacts, violating the principle of least privilege and making secrets management impossible. Option C is wrong because hardcoding credentials in environment variables is insecure; environment variables can be viewed in the Lambda console, CloudWatch logs, or through AWS CLI, and they are not encrypted by default, leading to potential credential leakage. Option D is wrong because database temporary tokens generated on the fly (e.g., using IAM database authentication for RDS) are a valid security practice for some databases, but the question specifically asks about protecting database credentials; temporary tokens are not credentials themselves but an alternative authentication method, and the option does not specify how the initial secret (e.g., the token generation key) is secured, making it an incomplete or misleading answer in this context.

20
MCQeasy

A security analyst is reviewing application logs and notices that a large number of requests from a single IP address are attempting to access a REST API endpoint with invalid session tokens. Which cloud-based mitigation is MOST effective at blocking such automated attacks?

A.Rotate API keys more frequently
B.Implement cross-origin resource sharing (CORS) policies
C.Configure a web application firewall (WAF) with rate limiting and IP blacklisting
D.Require encryption of session tokens
AnswerC

A WAF inspects HTTP traffic and applies rate limiting plus IP blacklisting, throttling or dropping the abusive source before requests reach the API. This blocks automated token-guessing floods more effectively than host-level or identity controls.

Why this answer

A Web Application Firewall (WAF) with rate limiting and IP blacklisting directly addresses the described attack: a single IP flooding a REST API with invalid session tokens. Rate limiting throttles the number of requests from that IP, while IP blacklisting blocks it entirely, preventing automated brute-force or credential-stuffing attempts at the cloud edge before they reach the application.

Exam trap

The trap here is that candidates may confuse session token management (e.g., rotation, encryption) with the need for a perimeter defense that controls request volume and source, leading them to pick options that address token validity rather than the automated, high-volume nature of the attack.

How to eliminate wrong answers

Option A is wrong because rotating API keys more frequently does not mitigate automated attacks using invalid session tokens; API keys are typically used for service-to-service authentication, not for user session validation, and rotation does not stop a flood of requests from a single IP. Option B is wrong because CORS policies control which origins (domains) can make cross-origin requests from a browser, but they do not block automated scripts or tools (e.g., cURL, Postman) that ignore CORS headers, nor do they rate-limit or blacklist IPs. Option D is wrong because requiring encryption of session tokens (e.g., via TLS) protects token confidentiality in transit but does not prevent an attacker from sending many requests with invalid tokens; encryption does not address the volume or source of the attack.

21
MCQhard

A software company develops a mobile application that communicates with a cloud backend using REST APIs. The application uses OAuth 2.0 with the authorization code grant and PKCE for authentication. After a security audit, the team identifies that the backend API accepts both a client secret (from the authorization code grant) and a PKCE code verifier. The security team wants to remove unnecessary attack surface. Which change should be made?

A.Switch to the implicit grant (response_type=token) to avoid client secrets
B.Keep both mechanisms but use short-lived tokens to reduce risk
C.Remove the client_secret parameter from the token endpoint and rely solely on PKCE
D.Require a stronger client secret (e.g., 256-bit) and store it in the app's encrypted storage
AnswerC

PKCE binds the authorization code to the client via a dynamically generated code verifier, so a public mobile client cannot protect a static secret. Removing client_secret eliminates a credential that could be extracted from the app bundle, satisfying the goal of reducing unnecessary attack surface.

Why this answer

PKCE (Proof Key for Code Exchange, RFC 7636) was specifically designed to secure the authorization code grant for public clients like mobile apps, where a client secret cannot be reliably kept confidential. By removing the client_secret parameter and relying solely on PKCE, the team eliminates an unnecessary attack surface—since the secret is effectively a static credential that can be extracted from the app binary—while maintaining strong protection against authorization code interception attacks. The backend should enforce PKCE verification using the code_challenge and code_verifier, making the client_secret redundant for public clients.

Exam trap

ISC2 often tests the misconception that removing the client_secret weakens security, when in fact for public clients (mobile apps, SPAs) PKCE makes the secret unnecessary and its removal reduces attack surface; candidates may incorrectly think keeping the secret adds a layer of defense, but it actually introduces a static credential that can be stolen.

How to eliminate wrong answers

Option A is wrong because switching to the implicit grant (response_type=token) would actually increase attack surface by exposing the access token directly in the URL fragment, making it vulnerable to leakage via browser history, referrer headers, and other side channels; it also removes the authorization code exchange step that PKCE protects. Option B is wrong because keeping both mechanisms does not reduce attack surface—it leaves the client_secret as an exploitable static credential that can be extracted from the app, and short-lived tokens do not mitigate the risk of secret theft or replay of the secret at the token endpoint. Option D is wrong because requiring a stronger client secret and storing it in encrypted storage still leaves the secret extractable from the mobile device at runtime (via memory dumps or reverse engineering), and encrypted storage keys are also accessible on the device; the fundamental issue is that public clients cannot securely hold secrets, so any reliance on a client_secret is a design flaw.

22
Multi-Selecthard

A cloud-native application team is adopting a secrets management service to eliminate hardcoded credentials in source code and configuration files. Which two practices best align with secure secrets management in the cloud? (Choose two.)

Select 2 answers
A.Commit encrypted secrets to the source repository so they are version-controlled alongside application code.
B.Store secrets in environment variables injected at container start to keep them out of the image.
C.Enable automatic rotation of secrets on a defined schedule and update dependent applications through the secrets manager.
D.Grant the application a workload identity so it retrieves secrets dynamically at runtime from the secrets manager.
E.Embed secrets in the container image and rely on image scanning to detect accidental exposure.
AnswersC, D

Automatic rotation limits the useful lifetime of a compromised secret and reduces the window of exposure. When rotation is coupled with dynamic retrieval from the secrets manager, applications pick up new values without redeployment, maintaining availability while improving security.

Why this answer

Secure secrets management favours dynamic, identity-based retrieval and routine rotation over static storage. Workload identity removes static credentials, and automatic rotation limits exposure windows; environment variables, encrypted secrets in repositories, and embedded secrets all retain long-lived or broadly accessible copies.

Exam trap

The trap here is believing that storing secrets in environment variables or encrypted in source control is equivalent to using a secrets manager with workload identity and rotation.

23
MCQmedium

A healthcare company runs a containerized patient portal on a managed Kubernetes service. Security policy requires that every container image be cryptographically verified as coming from the company's internal build pipeline before any pod is admitted to the cluster. The images are stored in a private OCI registry, and each build produces a signature using a private key held in a cloud key management service. Which mechanism should be implemented to enforce this policy at admission time?

A.Enable image vulnerability scanning in the registry and configure the cluster to pull only images with a CVSS score below a defined threshold.
B.Use a mutating admission webhook to inject an init container that runs a checksum comparison of the image layers against a manifest stored in the registry.
C.Configure an admission controller that validates image signatures against a trusted public key and rejects pods whose images are unsigned or signed by an untrusted key.
D.Apply a network policy that restricts pod egress to only the private registry, preventing images from being pulled from any other source.
AnswerC

Admission controllers that verify cryptographic signatures on container images can block any pod whose image lacks a valid signature from the trusted public key. This directly enforces the policy before the pod is scheduled, ensuring only images from the internal pipeline are admitted. It works with the existing KMS-held private key because the corresponding public key is what the controller checks.

Why this answer

Enforcing image provenance requires cryptographic verification at admission time, not merely scanning or network controls. An admission controller that checks signatures against a trusted public key ensures that only images signed by the internal pipeline's private key are admitted. This directly ties the cluster's admission decision to the build pipeline's signing authority, satisfying the policy while leveraging the existing KMS key infrastructure.

Exam trap

The trap here is assuming that vulnerability scanning or registry access controls prove image origin, when only cryptographic signature verification establishes provenance.

24
MCQhard

A company deploys microservices in Kubernetes. Each service communicates via gRPC with mutual TLS. A security assessment reveals that some services use self-signed certificates. What is the primary risk?

A.Inability to revoke certificates
B.Exposure of private keys in the container image
C.Increased latency due to certificate validation
D.Man-in-the-middle (MITM) attacks between services
AnswerD

Self-signed certificates lack a trusted certificate authority, so services cannot reliably verify each other's identity during the mutual TLS handshake. An attacker positioned between pods could present their own self-signed certificate and impersonate a legitimate service, intercepting gRPC traffic. This directly enables man-in-the-middle attacks, satisfying the scenario's mutual authentication requirement.

Why this answer

The primary risk of using self-signed certificates in a gRPC mutual TLS environment is that there is no trusted Certificate Authority (CA) to verify the identity of the communicating services. Without proper CA-signed certificates, an attacker can easily perform a man-in-the-middle (MITM) attack by presenting a forged self-signed certificate, intercepting and modifying gRPC traffic between microservices.

Exam trap

ISC2 often tests the misconception that self-signed certificates are only a problem for revocation or key exposure, when the core issue is the lack of trusted identity verification enabling MITM attacks.

How to eliminate wrong answers

Option A is wrong because self-signed certificates can still be revoked using mechanisms like CRLs or OCSP, though it is more cumbersome; the inability to revoke is not the primary risk. Option B is wrong because private keys are not inherently exposed in the container image; exposure is a separate misconfiguration issue, not a direct consequence of using self-signed certificates. Option C is wrong because certificate validation does not introduce significant latency; the overhead of TLS handshake is negligible compared to the security benefits, and self-signed certificates do not inherently increase validation time.

25
MCQeasy

A development team is building a web application that stores user passwords. The security architect recommends using a password hashing algorithm with a tunable work factor and a per-user random salt. Which approach best meets this recommendation?

A.Hash each password with SHA-256 and store the resulting digest alongside a random salt generated per user.
B.Encrypt each password with AES-256 using a key stored in a hardware security module and store the ciphertext.
C.Apply HMAC-SHA-256 to each password using a global application secret as the key and store the resulting tag.
D.Use a memory-hard password hashing function such as Argon2id with a calibrated cost parameter and a unique salt per user.
AnswerD

Argon2id is purpose-built for password storage, combining a tunable cost parameter with per-user salting to make offline guessing expensive and rainbow tables useless. The memory-hard design blunts GPU and ASIC attacks. This directly satisfies the architect's requirement for a tunable work factor and a per-user random salt while remaining a one-way function suitable for verification.

Why this answer

Storing passwords securely requires a one-way function designed for the purpose, with a per-user salt and an adjustable cost that can be raised as hardware improves. Argon2id provides memory hardness and a calibrated cost parameter, satisfying both parts of the architect's recommendation. Fast hashes, reversible encryption, and keyed hashes with a shared secret each fail to make large-scale offline guessing economically impractical.

Exam trap

The trap here is assuming that any salted hash is adequate, when the work factor and memory hardness are what actually determine resistance to offline cracking.

26
MCQeasy

A developer is tasked with securely storing a session token in a browser-based web application. Which storage mechanism is most secure?

A.HTTP-only cookies with Secure and SameSite flags
B.sessionStorage
C.URL query parameters
D.localStorage
AnswerA

HTTP-only cookies are inaccessible to JavaScript, so cross-site scripting cannot read the token, while Secure restricts transmission to HTTPS and SameSite blocks cross-site request forgery. This satisfies secure browser storage, unlike localStorage, which script can freely exfiltrate.

Why this answer

HTTP-only cookies with Secure and SameSite flags are the most secure storage mechanism for session tokens because they prevent client-side script access (mitigating XSS-based token theft), ensure transmission only over HTTPS (mitigating network eavesdropping), and restrict cross-origin request inclusion (mitigating CSRF). This combination aligns with OWASP best practices for session management, as the token is never exposed to JavaScript or sent over unencrypted channels.

Exam trap

ISC2 often tests the misconception that localStorage or sessionStorage is secure because they are 'client-side only,' but the trap is that both are fully accessible via JavaScript and thus vulnerable to XSS, whereas HTTP-only cookies are the only option that prevents script-level access.

How to eliminate wrong answers

Option B is wrong because sessionStorage is accessible via JavaScript, making it vulnerable to XSS attacks where an attacker can read the token directly. Option C is wrong because URL query parameters are logged in server logs, browser history, and referrer headers, exposing the session token to interception and persistent storage. Option D is wrong because localStorage persists data indefinitely and is fully accessible via JavaScript, offering no protection against XSS or CSRF, and lacks built-in expiration or secure transmission controls.

27
Multi-Selecthard

Which THREE of the following are effective controls to secure a RESTful API in the cloud?

Select 3 answers
A.Enabling CORS (Cross-Origin Resource Sharing) for all domains
B.Using HTTP basic authentication over plain HTTP
C.Implementing rate limiting and throttling
D.Enforcing strong authentication and authorization mechanisms
E.Validating and sanitizing all inputs to avoid injection attacks
AnswersC, D, E

Rate limiting and throttling cap request volume per client or key, mitigating brute-force, credential-stuffing and denial-of-service abuse against REST endpoints. This directly satisfies the stem's requirement for an effective control protecting cloud-hosted APIs from volumetric and enumeration attacks.

Why this answer

Option C is correct because rate limiting and throttling cap the number of requests a client can make in a given time window, mitigating brute-force, credential-stuffing, and denial-of-service abuse against API endpoints. Option D is correct because strong authentication (e.g., OAuth 2.0 tokens, mutual TLS) and authorization (e.g., scopes, RBAC, least privilege) ensure only verified, permitted identities can invoke API operations. Option E is correct because validating and sanitizing all inputs defends against injection flaws such as SQL injection, NoSQL injection, and command injection that arise from untrusted API parameters.

Option A is not appropriate because enabling CORS for all domains (wildcard Access-Control-Allow-Origin) exposes the API to cross-origin abuse rather than restricting access to trusted origins. Option B is not appropriate because HTTP Basic authentication over plain HTTP transmits base64-encoded credentials in cleartext, which can be intercepted; it should only be used over TLS.

Exam trap

ISC2 often tests the misconception that CORS is a security control that should be broadly enabled, when in fact it is a relaxation of the same-origin policy and must be tightly scoped to prevent cross-origin attacks.

28
MCQmedium

A healthcare SaaS provider exposes REST APIs to partner clinics. The security team must ensure that the API cannot be abused by replaying captured requests. The API already uses TLS 1.3 and OAuth 2.0 bearer tokens with short lifetimes. Which additional control best mitigates replay attacks against the API?

A.Enable HTTP Strict Transport Security (HSTS) with a long max-age on the API domain.
B.Increase the OAuth 2.0 token lifetime to reduce the frequency of token refresh calls.
C.Enforce mutual TLS between partner clinics and the API gateway.
D.Require a unique nonce and timestamp in each request, validated server-side against a replay cache.
AnswerD

A server-validated nonce combined with a timestamp ensures each request is unique and only accepted once within a defined window. Even if an attacker captures a request, the nonce will already be consumed or the timestamp will be stale, so the server rejects the replay. This directly mitigates replay attacks at the application layer.

Why this answer

Replay attacks occur when a valid request is captured and resent. Defenses must make each request unique and single-use. A server-validated nonce plus timestamp achieves this by rejecting duplicates and expired requests.

Transport security such as TLS or mTLS does not stop replay of already-authenticated application requests, and longer token lifetimes worsen exposure. HSTS is browser-focused and irrelevant to server-to-server API replay.

Exam trap

The trap here is assuming that transport-layer protections like TLS or mTLS automatically prevent application-layer replay of valid requests.

29
MCQhard

A company is deploying a containerized application on Kubernetes. The security team requires that containers run with the least privilege, and that any attempt to escalate privileges within a container is blocked. Which Kubernetes security context setting should be applied to the pod specification?

A.runAsNonRoot: true
B.capabilities: drop: ['ALL']
C.readOnlyRootFilesystem: true
D.allowPrivilegeEscalation: false
AnswerD

Setting allowPrivilegeEscalation to false prevents a container process from gaining more privileges than its parent, blocking mechanisms such as setuid binaries and file capabilities. This satisfies the stem's requirement that privilege escalation attempts within the container be blocked.

Why this answer

Setting `allowPrivilegeEscalation: false` in the pod's security context directly blocks any attempt by a container process to gain more privileges than its parent process, such as through setuid binaries or syscalls like `setuid()`. This satisfies the requirement to prevent privilege escalation within the container, aligning with the least privilege principle.

Exam trap

ISC2 often tests the distinction between preventing privilege escalation and other security controls like dropping capabilities or running as non-root, leading candidates to confuse capability removal with escalation prevention.

How to eliminate wrong answers

Option A is wrong because `runAsNonRoot: true` only ensures the container runs with a non-root user, but it does not block privilege escalation mechanisms (e.g., a non-root user could still execute a setuid binary to become root). Option B is wrong because dropping all capabilities (`capabilities: drop: ['ALL']`) removes kernel capabilities but does not prevent privilege escalation via other means like setuid binaries or file system capabilities. Option C is wrong because `readOnlyRootFilesystem: true` only makes the container's root filesystem read-only, which does not address privilege escalation at all.

30
MCQhard

A security architect is designing a multi-tenant SaaS application hosted on AWS. The application uses a shared Amazon RDS database with a tenant_id column to isolate data. The architect must ensure that tenants cannot access each other's data even if there is a vulnerability in the application layer. Which additional control should be implemented to enforce data isolation at the database level?

A.Use separate database schemas for each tenant.
B.Implement row-level security (RLS) policies in the database based on tenant_id.
C.Enable RDS encryption at rest using AWS KMS.
D.Configure security groups to restrict access to the RDS instance.
AnswerB

Row-level security (RLS) allows the database to enforce access control at the row level based on the tenant_id. Even if the application is compromised, the database will only return rows matching the tenant context set for the session. This provides a strong defense-in-depth control for multi-tenant isolation, assuming the application sets the tenant context correctly.

Why this answer

Row-level security (RLS) enforces data isolation at the database level by filtering rows based on the tenant context. Even if an attacker exploits the application, the database will only return rows for the current tenant, preventing cross-tenant data leakage. This defense-in-depth measure is critical for multi-tenant SaaS applications using a shared database, as it adds a layer of protection beyond application logic.

Exam trap

The trap here is assuming that encryption at rest or network controls like security groups can enforce tenant isolation, when they do not prevent queries from accessing other tenants' data.

31
Multi-Selecteasy

Which TWO of the following are common best practices for securing cloud application APIs? (Choose two.)

Select 2 answers
A.Implement rate limiting
B.Validate and sanitize all input
C.Disable HTTPS to reduce latency
D.Return detailed error messages for debugging
E.Allow all origins with CORS
AnswersA, B

Rate limiting prevents DDoS and brute force.

Why this answer

Rate limiting is a critical best practice for securing cloud application APIs because it prevents abuse by limiting the number of requests a client can make within a specific time window. This mitigates brute-force attacks, denial-of-service (DoS) attacks, and resource exhaustion. By enforcing rate limits, the API maintains availability and protects backend services from being overwhelmed.

Exam trap

ISC2 often tests the misconception that disabling HTTPS improves performance for cloud APIs, but the correct priority is always encryption for data in transit, even at the cost of slight latency.

32
MCQeasy

A DevOps team wants to prevent insecure code from being deployed to production. Which gate should be implemented in the CI/CD pipeline?

A.Automated security scanning with failure conditions
B.Run penetration testing after release
C.Dependency scanning only on weekly basis
D.Manual code review after deployment
AnswerA

Automated security scanning with failure conditions blocks the pipeline when vulnerabilities are detected, directly preventing insecure code from reaching production. This satisfies the stem's deployment-prevention constraint by enforcing a hard gate rather than advisory reporting, ensuring builds fail before artefacts are promoted.

Why this answer

Automated security scanning with failure conditions (option A) is the correct gate because it enforces security checks directly within the CI/CD pipeline, preventing any code that fails static application security testing (SAST) or software composition analysis (SCA) from progressing to production. This shift-left approach ensures that vulnerabilities are caught before deployment, aligning with DevSecOps principles and reducing risk.

Exam trap

ISC2 often tests the misconception that any security activity after deployment (like penetration testing or manual review) can serve as a preventive gate, when in fact only automated checks with failure conditions integrated into the pipeline can block insecure code before it reaches production.

How to eliminate wrong answers

Option B is wrong because running penetration testing after release does not prevent insecure code from being deployed; it only identifies vulnerabilities post-deployment, which violates the principle of shifting security left. Option C is wrong because dependency scanning only on a weekly basis introduces a significant delay, allowing vulnerable dependencies to be deployed before they are detected, whereas real-time scanning in the pipeline is needed. Option D is wrong because manual code review after deployment cannot block insecure code from reaching production; it is a reactive measure that does not serve as a pipeline gate.

33
MCQmedium

A financial services company is adopting a cloud-native microservices architecture. They want to ensure that only authorized services can communicate with each other, and that all inter-service communication is encrypted. Which of the following is the BEST approach?

A.Use network security groups to restrict traffic between service subnets
B.Implement a service mesh with mutual TLS (mTLS) and fine-grained access policies
C.Connect services using VPC peering and enable encryption in transit
D.Deploy an API gateway and route all internal traffic through it
AnswerB

A service mesh with mutual TLS authenticates both ends of every connection and encrypts traffic in transit, while fine-grained access policies enforce which services may call which. This satisfies the requirement for authorised, encrypted inter-service communication across the microservices architecture.

Why this answer

A service mesh with mutual TLS (mTLS) provides both encryption and identity-based authorization for inter-service communication. mTLS ensures that each service presents a valid certificate, proving its identity, and the mesh's control plane enforces fine-grained access policies (e.g., which services can call which endpoints). This directly meets the requirement for authorized, encrypted communication in a cloud-native microservices architecture.

Exam trap

A common misconception is that network-layer controls (like NSGs or VPC peering) are sufficient for service-to-service security, but the CCSP emphasizes that cloud-native architectures require identity-based authentication and encryption at the application or transport layer, which only a service mesh with mTLS provides.

How to eliminate wrong answers

Option A is wrong because network security groups (NSGs) operate at the network layer (IP/port) and cannot authenticate service identities or provide encryption; they only filter traffic based on source/destination IPs and ports, which is insufficient for service-level authorization in a dynamic microservices environment. Option C is wrong because VPC peering connects entire virtual networks and does not inherently enforce service-level authorization or mutual authentication; while encryption in transit can be enabled (e.g., IPsec), it lacks the fine-grained, identity-based access control that mTLS provides. Option D is wrong because an API gateway is designed for external traffic management and routing, not for internal service-to-service communication; routing all internal traffic through a single gateway creates a bottleneck, adds latency, and does not provide per-service mutual authentication or encryption at the transport layer.

34
MCQhard

A financial services company deploys a containerized application on Amazon ECS with Fargate. The application needs to access an encrypted RDS database. The security policy mandates that database credentials must never be stored in the application code or configuration files and must be rotated automatically every 90 days. Which solution should the DevOps team implement to satisfy these requirements?

A.Store credentials in AWS Secrets Manager, grant ECS task role access, and enable automatic rotation
B.Encrypt credentials with AWS KMS and pass them as environment variables during task definition
C.Store credentials in AWS Systems Manager Parameter Store (SecureString) and retrieve them at container startup
D.Use a secrets vault like Hashicorp Vault deployed on EC2 and mount secrets via sidecar container
AnswerA

Secrets Manager holds credentials outside code and configuration, the ECS task role grants access without static keys, and native rotation satisfies the 90-day mandate automatically. This meets both stated constraints: no embedded credentials and scheduled rotation.

Why this answer

AWS Secrets Manager is the correct choice because it is designed to securely store, retrieve, and automatically rotate database credentials on a schedule (e.g., every 90 days) without storing them in code or configuration. By granting the ECS task role (via IAM) permission to access the secret, the Fargate task can retrieve the credentials at runtime using the AWS SDK or CLI, ensuring they are never hardcoded. This satisfies both the no-storage-in-code and automatic rotation requirements mandated by the security policy.

Exam trap

ISC2 often tests the distinction between AWS Secrets Manager and Systems Manager Parameter Store, where candidates mistakenly choose Parameter Store because it is cheaper, but they overlook that Secrets Manager provides native automatic rotation for RDS credentials, which is explicitly required by the policy.

How to eliminate wrong answers

Option B is wrong because passing encrypted credentials as environment variables in the task definition still embeds them in the container's environment, which violates the policy of never storing credentials in code or configuration files, and it does not provide automatic rotation. Option C is wrong because AWS Systems Manager Parameter Store (SecureString) can store encrypted secrets but does not natively support automatic rotation of RDS database credentials; it requires custom Lambda functions or additional services to implement rotation, making it less suitable for the 90-day rotation requirement. Option D is wrong because deploying Hashicorp Vault on EC2 adds operational overhead, requires managing the EC2 instances and Vault cluster, and does not integrate natively with ECS Fargate's task role for seamless credential retrieval; it also does not automatically rotate RDS credentials without additional configuration.

35
MCQeasy

A team is adopting DevSecOps. Which practice best integrates security into the development lifecycle?

A.Security awareness training
B.Annual penetration testing
C.Automated security testing in CI/CD pipeline
D.Manual code review before release
AnswerC

Embedding automated security testing into the CI/CD pipeline shifts detection left, so vulnerabilities and misconfigurations are caught at build time rather than after deployment. This continuous, tool-driven gate is what actually integrates security into the development lifecycle, satisfying the DevSecOps adoption requirement in the stem.

Why this answer

Automated security testing in the CI/CD pipeline (Option C) is the correct practice because it embeds security checks—such as static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA)—directly into the build and deployment process. This ensures that vulnerabilities are detected and remediated early, aligning with the DevSecOps principle of 'shifting left' and enabling continuous security validation without slowing down development velocity.

Exam trap

ISC2 often tests the misconception that manual or periodic security activities (like annual pen tests or pre-release code reviews) are sufficient for DevSecOps, when the core requirement is continuous, automated security integration within the CI/CD pipeline itself.

How to eliminate wrong answers

Option A is wrong because security awareness training, while important for culture, is a people-focused activity that does not integrate automated, code-level security checks into the development lifecycle; it lacks the technical enforcement needed for continuous security in CI/CD. Option B is wrong because annual penetration testing is a point-in-time, manual assessment that occurs long after code is deployed, failing to provide the continuous, automated feedback required in a DevSecOps pipeline to catch vulnerabilities during development. Option D is wrong because manual code review before release is a gate-based, human-dependent process that introduces delays and inconsistency, and it does not scale or integrate with automated CI/CD workflows, whereas DevSecOps demands automated, frequent security validation.

36
Multi-Selectmedium

Which TWO of the following are considered best practices for securing containerized applications in a cloud environment?

Select 2 answers
A.Run containers with a non-root user.
B.Enable SSH inside the container for remote administration.
C.Use the 'latest' tag for base images to get the newest features.
D.Include debugging tools inside the container for troubleshooting.
E.Use a read-only filesystem for the container.
AnswersA, E

Running containers as a non-root user removes the default root privileges inside the container namespace, so a compromised process cannot escalate to host-level actions or write to protected paths. This directly reduces the blast radius of container breakout, satisfying the best-practice requirement for securing containerised cloud workloads.

Why this answer

Option A is correct because running containers with a non-root user (via the USER directive in the Dockerfile or runAsNonRoot/runAsUser in a Kubernetes securityContext) enforces least privilege, so a container breakout or compromised process cannot gain root-level access to the host or mounted resources. Option E is correct because mounting the container's root filesystem as read-only (docker run --read-only or readOnlyRootFilesystem: true in Kubernetes) prevents attackers from modifying binaries, writing malware, or persisting changes, and any needed writable paths can be explicitly mounted as tmpfs or volumes. Option B is not a best practice: enabling SSH inside a container increases the attack surface, bloats the image, and contradicts the immutable, single-process container model; administration should use docker exec, kubectl exec, or orchestration APIs instead.

Option C is wrong because the 'latest' tag is mutable and non-deterministic, breaking reproducibility and potentially pulling in unvetted or vulnerable base images; images should be pinned to specific immutable digests or version tags. Option D is also wrong because bundling debugging tools enlarges the attack surface and image size; troubleshooting should be done with ephemeral debug containers or sidecars rather than shipping tools in production images.

Exam trap

ISC2 often tests the misconception that SSH or debugging tools are necessary for container management, when in fact they violate the immutable and ephemeral principles of container security; the trap is that candidates confuse traditional server administration with cloud-native container operations.

37
MCQeasy

A retail company is migrating its monolithic e-commerce application to containers on a managed Kubernetes service. The security architect wants to ensure that if a container is compromised, the attacker cannot use the container's credentials to access the underlying node's filesystem or other pods' volumes. Which Kubernetes feature should be configured to meet this requirement?

A.Role-Based Access Control (RBAC) to limit service account permissions
B.NetworkPolicy to restrict pod-to-pod traffic
C.Pod Security Admission with the restricted profile
D.Runtime sandboxing with gVisor or Kata Containers
AnswerD

Runtime sandboxing such as gVisor or Kata Containers provides a stronger isolation boundary between the container and the host kernel or node. gVisor intercepts syscalls in user space, while Kata runs containers in lightweight VMs. Both reduce the ability of a compromised container to access the node filesystem or other pods' volumes, directly meeting the isolation requirement.

Why this answer

The requirement is strong runtime isolation so a compromised container cannot reach the node or other pods' data. Runtime sandboxing with gVisor or Kata Containers creates a boundary beyond standard Linux namespaces and cgroups. Pod Security Admission, NetworkPolicy, and RBAC are valuable but address configuration hardening, network traffic, and API authorization respectively, not filesystem and volume isolation from the host.

Exam trap

The trap here is confusing network or API authorization controls with runtime isolation of the container from the host and other workloads.

38
MCQmedium

An organization uses infrastructure as code (IaC) to deploy cloud resources. The security team wants to prevent misconfigurations such as open security groups from being deployed. Which two practices should be integrated into the IaC pipeline? (Select TWO)

A.Limit access to the cloud management console
B.Perform manual code reviews for every change
C.Segment the network using security groups
D.Implement policy-as-code to enforce security rules
E.Use automated security scanning tools for IaC templates
AnswerD, E

Policy-as-code encodes security rules, such as prohibiting open security groups, as machine-enforceable policies evaluated during the pipeline. This blocks non-compliant templates before deployment, satisfying the requirement to prevent misconfigurations rather than detect them after resources are provisioned.

Why this answer

Policy-as-code (D) allows security rules to be defined in a machine-readable format (e.g., using Open Policy Agent or HashiCorp Sentinel) and automatically evaluated during the IaC pipeline, preventing non-compliant configurations from being deployed. Automated security scanning tools (E) analyze IaC templates (e.g., Terraform, CloudFormation) for known misconfigurations, such as overly permissive security group rules, before they reach production. Together, these practices enforce security guardrails early in the development lifecycle.

Exam trap

ISC2 often tests the distinction between operational controls (like manual reviews or console access) and automated pipeline controls (like policy-as-code and scanning), expecting candidates to recognize that only automated, integrated checks can prevent misconfigurations at the code level before deployment.

How to eliminate wrong answers

Option A is wrong because limiting access to the cloud management console is an administrative control that does not prevent misconfigurations in IaC templates; it only restricts who can manually make changes after deployment. Option B is wrong because manual code reviews are slow, error-prone, and cannot scale to catch all misconfigurations, especially in large IaC codebases; automated checks are required for consistent enforcement. Option C is wrong because segmenting the network using security groups is a network architecture practice, not a pipeline integration; it does not prevent misconfigurations in the IaC templates themselves.

39
MCQhard

A cloud application uses a managed API gateway to expose REST APIs. The security team wants to ensure that clients cannot bypass the gateway and call backend services directly. The backend services run on private subnets and are fronted by an internal load balancer. Which control should be implemented to enforce this requirement?

A.Enable TLS mutual authentication between the API gateway and backend services
B.Use API keys validated at the API gateway only
C.Configure the backend services to accept traffic only from the API gateway's security group or service account
D.Deploy a web application firewall (WAF) on the backend services
AnswerC

Restricting backend ingress to the API gateway's identity ensures that only the gateway can forward requests. This can be done with security groups, network ACLs, or IAM-based authentication depending on the cloud provider. It directly prevents clients from bypassing the gateway, because direct calls from other sources are denied at the network or identity layer.

Why this answer

The only way to prevent clients from bypassing the API gateway is to restrict backend ingress to the gateway's identity. This can be enforced through security groups, network policies, or IAM roles. mTLS, WAFs, and gateway-only API key validation add security but do not block direct network access, so they cannot guarantee that all traffic flows through the gateway.

Exam trap

The trap here is assuming that mTLS or API keys at the gateway prevent bypass, when network-level or identity-level restrictions on the backend are required.

40
MCQhard

A cloud security architect is designing a CI/CD pipeline for a containerized application. The requirement is that container images be cryptographically signed by the build system and that only images with valid signatures be admitted to the production Kubernetes cluster. Which combination of controls best achieves this?

A.Store images in a private registry and restrict registry access using IAM policies.
B.Scan images for vulnerabilities during the build and block the pipeline if critical findings are detected.
C.Sign images with a key managed by the build system and enforce signature verification with an admission controller that rejects unsigned images.
D.Enable image layer caching in the build system to speed up builds and reduce exposure to tampering.
AnswerC

Cryptographic signing by the build system establishes provenance, and an admission controller that verifies signatures before allowing pod creation enforces the policy at deploy time. Together they ensure only trusted images run in production, satisfying both the signing and admission requirements.

Why this answer

Meeting the requirement needs two complementary controls: cryptographic signing at build time to prove provenance, and admission-time verification to reject unsigned or tampered images. Scanning, registry access controls, and caching address different concerns and cannot enforce signature validity when pods are scheduled.

Exam trap

The trap here is treating vulnerability scanning or private registry access as equivalent to image signing and admission verification, when none of those establishes or checks cryptographic provenance.

41
Multi-Selecteasy

Which TWO best practices help secure a cloud application's runtime environment?

Select 2 answers
A.Use immutable infrastructure
B.Implement host-based intrusion detection
C.Run applications with least privilege
D.Enable automatic patching of dependencies
E.Use container orchestration platform
AnswersA, C

Immutable infrastructure replaces running instances rather than patching them in place, so configuration drift and persistent compromise are eliminated on each deployment. This satisfies the runtime security requirement by ensuring every instance starts from a known, verified image.

Why this answer

Option A (Use immutable infrastructure) is correct because replacing rather than modifying running instances eliminates configuration drift and prevents attackers from persisting changes on a compromised host, since any tampering is discarded when the instance is rebuilt from a known-good image. Option C (Run applications with least privilege) is correct because granting each process, service account, and container only the minimum permissions it needs limits the blast radius of a compromise and blocks privilege-escalation paths within the runtime environment. Option B (host-based intrusion detection) is a detective control that can complement runtime security but does not itself harden or secure the environment, and it is often impractical in ephemeral cloud workloads.

Option D (automatic patching of dependencies) addresses vulnerability management in the build/supply chain rather than securing the runtime environment itself, and blind auto-patching can introduce instability. Option E (container orchestration platform) is a deployment technology, not a security best practice, and using it without proper configuration can actually widen the attack surface.

Exam trap

ISC2 often tests the distinction between security controls that are preventive (like immutable infrastructure and least privilege) versus detective or reactive controls (like HIDS), leading candidates to mistakenly select host-based intrusion detection as a runtime security best practice.

42
MCQhard

A cloud application uses a service mesh for inter-service communication. The security team wants to enforce mutual TLS (mTLS) between all services and ensure that service identities are verified. What is the most effective way to achieve this?

A.Set up Kerberos authentication between services
B.Configure a VPN between all service subnets
C.Implement IPsec in the network layer
D.Use the service mesh's built-in mTLS and certificate management
AnswerD

The service mesh's built-in mTLS issues and rotates workload certificates, authenticating service identities via SPIFFE-style identities without application code changes. This satisfies the stem's requirement to enforce mutual TLS and verify service identities across all inter-service communication automatically.

Why this answer

The service mesh's built-in mTLS and certificate management is the most effective approach because it provides automatic, transparent mutual TLS encryption and identity verification at the application layer, using X.509 certificates issued by the mesh's certificate authority (e.g., Istio's Citadel or Linkerd's identity controller). This ensures that every inter-service communication is authenticated and encrypted without requiring changes to application code, and it integrates directly with the service mesh's identity model (e.g., Kubernetes service accounts).

Exam trap

ISC2 often tests the misconception that network-layer encryption (IPsec or VPN) is sufficient for service-to-service authentication, but the key requirement here is per-service identity verification at the application layer, which only a service mesh's mTLS with certificate management can provide.

How to eliminate wrong answers

Option A is wrong because Kerberos is a network authentication protocol that requires a centralized Key Distribution Center (KDC) and is not designed for per-request mTLS in a service mesh; it adds complexity and does not provide transport-layer encryption natively. Option B is wrong because a VPN encrypts traffic at the network layer between subnets but does not provide per-service identity verification or mutual authentication at the application layer, and it cannot enforce mTLS between individual services within the same subnet. Option C is wrong because IPsec operates at the network layer (Layer 3) and can encrypt traffic between hosts or subnets, but it lacks the granularity to verify individual service identities and does not integrate with service mesh certificate management for dynamic, short-lived certificates.

43
MCQmedium

A development team is building a cloud-native application that stores user session data in a managed Redis service. The security architect requires that session data be encrypted at rest and that the application authenticate to Redis without embedding static credentials in code. Which approach best meets these requirements?

A.Rely on network isolation and Redis AUTH with a long-lived password rotated quarterly
B.Enable encryption at rest and store the Redis password in an environment variable
C.Enable encryption at rest on the Redis service and use IAM authentication with short-lived tokens
D.Use client-side encryption before writing to Redis and authenticate with a shared secret stored in a configuration file
AnswerC

Managed Redis services often support encryption at rest and IAM-based authentication, which issues temporary credentials tied to the workload's identity. This eliminates static passwords in code and satisfies both encryption and credential management requirements. It aligns with cloud security best practices for secretless authentication and data protection.

Why this answer

The best approach combines native encryption at rest with IAM authentication using short-lived tokens. This removes static credentials from code and leverages the cloud provider's identity system. Storing passwords in environment variables, configuration files, or using long-lived shared secrets all violate the requirement to avoid static credentials, even if encryption at rest is enabled.

Exam trap

The trap here is thinking that environment variables or configuration files are secure places for credentials, when they are still static secrets that can leak.

44
MCQhard

A cloud security team is reviewing a CI/CD pipeline that builds and deploys a containerized application to a production cluster. The pipeline runs in a cloud build service and uses a long-lived service account key stored as a secret in the pipeline configuration to push images and update deployments. A recent audit flagged this as a risk. Which change best reduces the risk of credential compromise while maintaining automated deployments?

A.Grant the service account broader permissions so that fewer distinct credentials are needed across pipeline stages.
B.Rotate the service account key on a weekly schedule and store the new key in the same pipeline secret store.
C.Replace the long-lived key with short-lived credentials obtained through workload identity federation between the build service and the cloud provider.
D.Encrypt the service account key with a customer-managed key and restrict access to the pipeline configuration to a small group of administrators.
AnswerC

Workload identity federation lets the build service exchange its own identity for short-lived cloud credentials, eliminating stored long-lived keys. If a credential is compromised, it expires quickly and is scoped to the build workload. This reduces the blast radius of credential theft while preserving automated deployments, directly addressing the audit finding.

Why this answer

Storing long-lived service account keys in a pipeline creates a persistent credential that attackers can steal and reuse. Workload identity federation replaces that key with short-lived tokens bound to the build service's identity, so credentials expire automatically and are scoped to the workload. This maintains automation while removing the stored secret, which is the most effective way to reduce credential compromise risk.

Exam trap

The trap here is assuming that encrypting or rotating a long-lived key fixes the risk, when the fundamental problem is the existence of a persistent credential that can be stolen.

45
MCQeasy

A company is implementing a secure software development lifecycle (SSDLC) for its cloud-native applications. Which practice should be automated to detect vulnerabilities early in the development process?

A.Static application security testing (SAST)
B.Penetration testing in production
C.Dynamic application security testing (DAST)
D.Manual code review
AnswerA

SAST scans source code without executing it, detecting vulnerabilities such as injection flaws during coding. Automating it in the CI pipeline satisfies the SSDLC constraint of finding defects early, before deployment, when remediation is cheapest and least disruptive.

Why this answer

Static application security testing (SAST) analyzes source code, bytecode, or binaries without executing the application, making it ideal for early detection of vulnerabilities during the coding phase of the SSDLC. By integrating SAST into the CI/CD pipeline, developers receive immediate feedback on security flaws such as SQL injection or buffer overflows, enabling remediation before the code is built or deployed. This aligns with the 'shift left' principle, catching issues when they are cheapest and easiest to fix.

Exam trap

ISC2 often tests the distinction between SAST (white-box, early) and DAST (black-box, late), and the trap here is that candidates mistakenly choose DAST because they confuse 'dynamic' with 'automated,' forgetting that DAST requires a running application and cannot detect vulnerabilities in source code.

How to eliminate wrong answers

Option B is wrong because penetration testing in production occurs after deployment, not early in development, and can introduce risks to live systems. Option C is wrong because dynamic application security testing (DAST) requires a running application to test, making it a later-stage practice that cannot detect vulnerabilities in code before it is compiled or deployed. Option D is wrong because manual code review is not automated and is slower, less consistent, and more error-prone than automated SAST, failing to meet the requirement for automation to detect vulnerabilities early.

46
Multi-Selecthard

Which THREE are best practices for implementing secrets management in cloud applications?

Select 3 answers
A.Embed secrets in application logs for debugging
B.Store secrets in version control repositories
C.Use a dedicated secrets management service
D.Rotate secrets regularly
E.Encrypt secrets at rest and in transit
AnswersC, D, E

A dedicated secrets management service centralises storage, access control and auditing, removing hard-coded credentials from source and configuration. It enforces least-privilege retrieval and enables automated rotation, directly satisfying the best-practice requirement for controlling secret sprawl across cloud applications.

Why this answer

Option C is correct because a dedicated secrets management service (e.g., AWS Secrets Manager, Azure Key Vault, HashiCorp Vault) centralizes storage, enforces access control via IAM policies, and provides audit logging and programmatic retrieval, which is the recommended pattern for cloud applications. Option D is correct because regularly rotating secrets limits the blast radius of a leaked credential and is a core requirement of standards like PCI DSS and NIST SP 800-57; managed services can automate rotation via Lambda or native rotation policies. Option E is correct because secrets must be encrypted at rest (e.g., AES-256 via KMS) and in transit (TLS 1.2+) to prevent exposure from compromised storage or network interception.

Option A is not a best practice because embedding secrets in application logs exposes them to anyone with log access and defeats the purpose of secret confidentiality. Option B is not a best practice because storing secrets in version control repositories persists them in history, making them retrievable even after deletion and widely accessible to anyone with repo access.

Exam trap

ISC2 often tests the misconception that logging secrets is acceptable for debugging (Option A) or that version control with .gitignore is sufficient to protect secrets (Option B), but the CCSP exam emphasizes that secrets must never be stored in logs or repositories, and must always be managed via dedicated, rotation-capable services.

47
MCQmedium

A cloud application development team is using a public API gateway to expose microservices. The security team wants to protect the APIs from common web vulnerabilities such as SQL injection and cross-site scripting (XSS). Which control should be implemented at the API gateway?

A.API rate limiting
B.Mutual TLS (mTLS) authentication
C.Web application firewall (WAF)
D.OAuth 2.0 token validation
AnswerC

A WAF inspects incoming HTTP requests and can block or sanitize malicious payloads that target vulnerabilities like SQL injection and XSS. Deploying a WAF at the API gateway provides a centralized enforcement point for all microservices, reducing the need to implement protections in each service. It can be configured with rule sets such as OWASP Core Rule Set to detect and mitigate common attacks, thus protecting the APIs from exploitation.

Why this answer

A web application firewall (WAF) deployed at the API gateway is the appropriate control to protect against SQL injection and XSS. It inspects HTTP requests and can block or sanitize malicious inputs before they reach the microservices. While other controls like rate limiting, mTLS, and OAuth 2.0 are important for availability, authentication, and authorization, they do not analyze request content for injection attacks.

A WAF provides the necessary application-layer protection.

Exam trap

The trap here is assuming that authentication or rate limiting controls also protect against injection attacks, when they operate at different layers and do not inspect payload content.

48
MCQeasy

A company is migrating a legacy application to the cloud. The application uses hardcoded database credentials. Which secure development practice should be implemented to address this?

A.Use code signing for all deployments
B.Implement input validation on all user inputs
C.Enable encryption at rest for the database
D.Use a secrets management service
AnswerD

A secrets management service stores database credentials outside the codebase and injects them at runtime, removing hardcoded values from the application. This satisfies the secure development requirement by centralising rotation, access control and auditing of those credentials.

Why this answer

Hardcoded database credentials in application code create a severe security risk because they are exposed in version control, logs, and static analysis. Using a secrets management service (e.g., AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) allows credentials to be stored securely, rotated automatically, and accessed at runtime via API calls, eliminating the need to embed secrets in code. This aligns with the principle of least privilege and secure credential management in cloud application security.

Exam trap

ISC2 often tests the distinction between 'protecting data at rest' (encryption) and 'protecting access credentials' (secrets management), leading candidates to mistakenly choose encryption at rest when the real issue is credential exposure in code.

How to eliminate wrong answers

Option A is wrong because code signing ensures the integrity and authenticity of the deployed code, but it does not address the problem of hardcoded credentials—it does not remove secrets from the codebase. Option B is wrong because input validation prevents injection attacks (e.g., SQLi, XSS) by sanitizing user-supplied data, but it has no effect on static credentials embedded in the application source code. Option C is wrong because encryption at rest protects data stored in the database (e.g., on disk), but it does not protect the credentials used to access the database—those credentials remain exposed in the code.

49
MCQhard

A healthcare organization runs a multi-tenant SaaS application on a public cloud. Each tenant's data is stored in a shared database with a tenant identifier column. A penetration test shows that a crafted API request can return records belonging to another tenant. The application already authenticates users and validates their tenant membership at login. Which control most directly addresses the root cause of this finding?

A.Enforce tenant scoping in the data access layer by deriving the tenant identifier from the authenticated session and applying it to every query, ignoring any tenant value supplied by the client.
B.Move each tenant's data into a separate database schema and grant the application role access only to the schema matching the authenticated tenant.
C.Require tenants to authenticate with mutual TLS and bind each client certificate to a tenant identifier that the API validates on every request.
D.Add a web application firewall rule that inspects API request bodies for tenant identifier values that differ from the authenticated user's tenant.
AnswerA

The vulnerability is broken object-level authorization: the API trusts a client-supplied tenant identifier instead of binding queries to the authenticated principal. Deriving the tenant from the validated session and injecting it into every query ensures a user can never read another tenant's rows, regardless of what the request contains. This fixes the root cause at the point where data is retrieved.

Why this answer

The penetration test demonstrates broken object-level authorization, where the API accepts a client-controlled tenant identifier and uses it to scope queries. The durable fix is to derive the tenant from the authenticated session and enforce that scope in the data access layer so client input can never widen it. WAF rules, schema separation, and mutual TLS each add defense in depth but do not correct the authorization flaw that allows cross-tenant reads.

Exam trap

The trap here is treating a cross-tenant data leak as an authentication or network problem when the actual defect is server-side authorization of each data access.

50
MCQmedium

A company is adopting a serverless architecture using AWS Lambda. The security team is concerned about potential injection attacks via event payloads. Which practice is most effective at mitigating such attacks?

A.Use a web application firewall (WAF) in front of the API Gateway
B.Assign the least privilege IAM role to each Lambda function
C.Validate and sanitize all input data from event sources
D.Encrypt environment variables containing sensitive configuration
AnswerC

Validating and sanitising event payloads strips or rejects malicious content before Lambda processes it, breaking the injection path regardless of event source. This addresses the stem's concern directly, since serverless functions cannot rely on network-layer defences to inspect event data.

Why this answer

Serverless functions like AWS Lambda are directly invoked by event payloads, and without input validation and sanitization, an attacker can inject malicious code (e.g., SQL, NoSQL, OS commands) that the function executes. This is the most effective mitigation as it addresses the root cause at the application layer, regardless of any perimeter controls.

Exam trap

ISC2 often tests the misconception that perimeter controls (like WAFs) or IAM permissions are sufficient to prevent application-layer attacks, but the trap here is that injection vulnerabilities are code-level flaws that only input validation can directly remediate.

How to eliminate wrong answers

Option A is wrong because a WAF operates at the HTTP/HTTPS layer and cannot inspect or block injection attacks that originate from non-HTTP event sources (e.g., S3 events, DynamoDB Streams, SQS messages) or from payloads that are already inside the trusted network path. Option B is wrong because least privilege IAM roles control what resources the Lambda function can access (e.g., read from a database), but they do not prevent the function from executing malicious input passed in the event payload. Option D is wrong because encrypting environment variables protects sensitive configuration data at rest and in transit, but it has no effect on injection attacks that exploit unsanitized input in the event payload.

51
MCQmedium

A company is adopting DevSecOps and wants to incorporate security testing into their continuous integration pipeline. They have decided to run SAST (static analysis) and SCA (software composition analysis) tools. Which of the following is the PRIMARY reason for including SCA in addition to SAST?

A.To detect insecure runtime behavior
B.To identify known vulnerabilities in third-party libraries and dependencies
C.To reduce false positives identified by SAST
D.To scan for vulnerabilities in custom APIs
AnswerB

SAST analyses your own source code for coding flaws, so it cannot detect risks inside compiled third-party packages. SCA inventories dependencies and maps them to known CVE databases, satisfying the stem's requirement to cover libraries pulled into the CI pipeline.

Why this answer

SCA (Software Composition Analysis) is specifically designed to identify known vulnerabilities in third-party libraries and dependencies by comparing their versions against public vulnerability databases like the National Vulnerability Database (NVD) or OWASP Dependency-Check. SAST (Static Application Security Testing) analyzes custom source code for security flaws but cannot inspect external libraries that are often pulled in via package managers (e.g., npm, Maven, pip). Including SCA ensures that the organization addresses supply chain risks, which is a primary goal in DevSecOps pipelines.

Exam trap

ISC2 often tests the distinction between SAST (custom code analysis) and SCA (third-party dependency analysis), and the trap here is that candidates may confuse SCA with DAST or think SCA can reduce SAST false positives, when in reality SCA addresses a completely different attack surface—open-source library vulnerabilities.

How to eliminate wrong answers

Option A is wrong because detecting insecure runtime behavior is the domain of DAST (Dynamic Application Security Testing) or IAST (Interactive Application Security Testing), not SCA, which focuses on static analysis of dependency manifests. Option C is wrong because SCA does not reduce false positives from SAST; false positive reduction is typically achieved by tuning SAST rules, using IAST for verification, or implementing manual triage processes. Option D is wrong because scanning for vulnerabilities in custom APIs is a function of SAST (for code-level flaws) or DAST (for runtime API endpoints), not SCA, which only analyzes third-party components and their known CVEs.

52
MCQhard

A company is implementing a serverless application using AWS Lambda. The function processes S3 events and writes to a DynamoDB table. Which of the following is the MOST secure way to grant the necessary permissions?

A.Use resource-based policies on the Lambda function
B.Attach a managed policy that grants full access to S3 and DynamoDB
C.Use the root user credentials of the AWS account
D.Create a custom IAM role with only the required actions on specific resources
AnswerD

A custom IAM role grants only the specific S3 read and DynamoDB write actions on named resource ARNs, enforcing least privilege. Lambda assumes this role at runtime, avoiding broad managed policies or long-lived access keys embedded in the function.

Why this answer

AWS Lambda functions require an IAM role (execution role) to access other AWS services. By creating a custom IAM role with only the required actions (e.g., s3:GetObject for the specific S3 bucket and dynamodb:PutItem for the specific DynamoDB table), you adhere to the principle of least privilege, minimizing the attack surface and ensuring secure, auditable access.

Exam trap

ISC2 often tests the misconception that resource-based policies on the Lambda function can grant the function permissions to other services, when in fact they only control invocation permissions, not the function's outbound access to resources like S3 or DynamoDB.

How to eliminate wrong answers

Option A is wrong because resource-based policies on a Lambda function control who can invoke the function, not what the function can access; they do not grant the function permissions to S3 or DynamoDB. Option B is wrong because attaching a managed policy that grants full access to S3 and DynamoDB violates least privilege, potentially allowing the function to perform unintended actions (e.g., delete data) and increasing the blast radius of a compromise. Option C is wrong because using root user credentials is a severe security risk—root credentials have unrestricted access, should never be used for programmatic access, and violate AWS best practices and compliance requirements.

53
MCQhard

A cloud provider's API is used by an application to retrieve secrets from a managed secrets store. The security team wants to ensure that if a secret is compromised, its use is limited to a short window and that all access is attributable to a specific workload identity. Which combination best meets these requirements?

A.Use the secrets store's dynamic secrets feature to issue short-lived credentials tied to the workload's authenticated identity, with audit logging of each issuance.
B.Store the secret in an environment variable on the compute instance and rotate it every 90 days using a scheduled job.
C.Encrypt the secret with a customer-managed key and require two administrators to approve each retrieval.
D.Embed the secret in the container image and rely on image signing to ensure only trusted images run.
AnswerA

Dynamic secrets generate credentials on demand with a short time-to-live and bind them to the requesting workload's authenticated identity. Each issuance is logged, providing attribution. If compromised, the credential expires quickly, limiting the window of use. This directly satisfies both the short-lived use and attribution requirements.

Why this answer

Dynamic secrets issued to an authenticated workload identity provide short-lived credentials and per-issuance audit trails. If a credential leaks, its TTL limits the damage, and logs attribute each issuance to a specific workload. Static secrets in environment variables, encrypted secrets with dual approval, and secrets embedded in images do not provide both short-lived use and workload-level attribution.

Exam trap

The trap here is assuming that encrypting a static secret or adding approval steps limits its use after compromise, when only short-lived, identity-bound credentials reduce the exposure window.

54
MCQeasy

A development team is building a cloud application and needs to store API keys and database passwords securely. The team wants to minimize management overhead and ensure automatic rotation of secrets. Which AWS service should they use?

A.AWS IAM roles
B.AWS Systems Manager Parameter Store
C.Amazon S3 with server-side encryption
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager is designed to store and manage secrets such as API keys and database passwords. It provides built-in rotation for supported services like RDS, Redshift, and DocumentDB, and allows custom rotation via Lambda. This reduces management overhead and enhances security by automatically rotating secrets, meeting the team's requirements.

Why this answer

AWS Secrets Manager is purpose-built for storing and managing secrets, offering automatic rotation for many AWS services and custom rotation via Lambda. This minimizes management overhead and ensures secrets are regularly rotated, reducing the risk of compromise. The team can focus on application development while Secrets Manager handles the lifecycle of secrets securely.

Exam trap

The trap here is assuming that Parameter Store provides automatic rotation like Secrets Manager, when it requires custom implementation.

55
MCQeasy

Which of the following is a key benefit of using a software composition analysis (SCA) tool in a cloud application security program?

A.Detects known vulnerabilities in open-source libraries
B.Enforces runtime policies
C.Simulates attacks on running applications
D.Identifies vulnerabilities in proprietary code
AnswerA

Software composition analysis inventories third-party and open-source dependencies, then matches their versions against vulnerability databases to flag known CVEs. This directly satisfies the stem's requirement by identifying inherited risk in libraries the development team did not author, which static code analysis of first-party code alone would miss.

Why this answer

SCA tools automate the identification of open-source components within a codebase and cross-reference them against databases like the National Vulnerability Database (NVD) to detect known vulnerabilities (CVEs). This is a key benefit because cloud applications often heavily rely on open-source libraries, and SCA provides a scalable way to manage that risk without manual auditing.

Exam trap

ISC2 often tests the distinction between SCA (open-source dependency scanning) and SAST (proprietary code scanning), so the trap here is confusing which tool analyzes which type of code, leading candidates to incorrectly select option D.

How to eliminate wrong answers

Option B is wrong because enforcing runtime policies is the function of a Runtime Application Self-Protection (RASP) tool or a cloud workload protection platform (CWPP), not an SCA tool which focuses on static analysis of dependencies. Option C is wrong because simulating attacks on running applications is the purpose of a dynamic application security testing (DAST) tool or a penetration testing framework, not SCA which does not execute code. Option D is wrong because identifying vulnerabilities in proprietary code is the domain of static application security testing (SAST) tools that analyze custom source code, whereas SCA specifically targets open-source and third-party components.

56
Multi-Selecthard

Which THREE of the following are valid techniques to protect application programming interfaces (APIs) from abuse?

Select 3 answers
A.Use API gateways to enforce authentication and authorization policies.
B.Use JSON Web Tokens (JWT) without encryption.
C.Use only HTTP GET requests for all API calls.
D.Implement rate limiting and throttling.
E.Require API keys or OAuth tokens for every request.
AnswersA, D, E

An API gateway centralises authentication and authorisation enforcement at the ingress point, validating tokens and applying policy before requests reach backend services. This prevents unauthenticated or unauthorised callers from invoking APIs, directly countering abuse such as credential-less enumeration and privilege escalation.

Why this answer

Option A is correct because an API gateway acts as a centralized enforcement point where authentication (e.g., validating OAuth 2.0 tokens or mTLS client certificates) and authorization policies (e.g., scope or role checks) are applied before requests reach backend services, blocking unauthenticated or unauthorized abuse. Option D is correct because rate limiting and throttling cap the number of requests a client can make per time window (e.g., 100 requests/minute per API key), mitigating brute-force, credential-stuffing, scraping, and denial-of-service abuse. Option E is correct because requiring an API key or OAuth token on every request ensures each call is tied to an identifiable, revocable principal, enabling per-client quotas, auditing, and immediate revocation of compromised credentials.

Option B is not a valid protection technique because an unencrypted JWT is only base64url-encoded and signed, not confidential—its payload can be read by anyone, so it does not protect the API from abuse and may leak sensitive claims. Option C is incorrect because restricting APIs to HTTP GET does not prevent abuse; GET requests can still be replayed, scraped, or flooded, and many legitimate operations require POST, PUT, or DELETE, so this neither authenticates nor limits callers.

Exam trap

The trap here is that candidates may think JWT without encryption is acceptable because JWTs are often signed (JWS), but the CCSP exam emphasizes that confidentiality is a separate requirement—signing alone does not protect sensitive data in the payload, and encryption (JWE) is mandatory when tokens contain private information.

57
MCQeasy

A company is moving a legacy application to the cloud. The application uses hard-coded passwords for database connections. Which secure development practice should be implemented to address this issue?

B.Input validation
C.Encryption at rest
D.Secrets management
AnswerD

Secrets management extracts hard-coded credentials into a dedicated vault that issues short-lived, rotated credentials at runtime, removing passwords from source and images. This directly satisfies the stem's constraint by eliminating the embedded database passwords that would otherwise leak through repositories and container layers.

Why this answer

Hard-coded passwords in application code violate the principle of least privilege and create a persistent security risk if the code is exposed. Secrets management (D) addresses this by storing database credentials in a secure, centralized vault (e.g., HashiCorp Vault, AWS Secrets Manager) and retrieving them at runtime via API calls, eliminating the need to embed passwords in source code or configuration files.

Exam trap

ISC2 often tests the distinction between 'encryption at rest' (protecting stored data) and 'secrets management' (protecting credentials used to access that data), leading candidates to confuse data protection with credential protection.

How to eliminate wrong answers

Option A is wrong because multi-factor authentication (MFA) is an identity verification mechanism for user access, not a method to securely store or manage application-level database credentials. Option B is wrong because input validation prevents injection attacks (e.g., SQL injection) by sanitizing user-supplied data, but it does not address the storage or retrieval of hard-coded passwords. Option C is wrong because encryption at rest protects data stored on disk (e.g., database files) from unauthorized access, but it does not prevent the exposure of credentials hard-coded in application code or configuration.

58
MCQmedium

A company wants to enforce that all API calls to its cloud services are authenticated and authorized. Which design pattern should be implemented?

A.Implement OAuth 2.0 with scopes
B.Use API keys with IP whitelisting
C.Allow basic authentication over HTTPS
D.Use shared secrets with HMAC
AnswerA

OAuth 2.0 with scopes satisfies the requirement by issuing access tokens that carry granular permissions, letting the resource server validate both caller identity and the specific operations each token authorises. Scopes constrain what an authenticated client may do, delivering authentication and fine-grained authorisation for every API call without exposing credentials.

Why this answer

OAuth 2.0 with scopes is the correct design pattern because it provides a standardized, token-based authorization framework that allows fine-grained access control to API resources. Scopes define specific permissions (e.g., read, write) and are validated by the resource server, ensuring that each API call is both authenticated (via the access token) and authorized (via the scopes). This aligns with the principle of least privilege and is widely adopted for securing cloud APIs.

Exam trap

The trap here is that candidates often confuse authentication (verifying identity) with authorization (granting permissions) and choose a method like API keys or basic auth that only authenticates, failing to address the authorization requirement explicitly stated in the question.

How to eliminate wrong answers

Option B is wrong because API keys with IP whitelisting only authenticate the client application, not the user or the request context, and IP whitelisting can be bypassed via spoofing or compromised networks; it lacks granular authorization. Option C is wrong because basic authentication over HTTPS sends credentials (username/password) in every request, which is vulnerable to credential leakage if the client or server is compromised, and it does not support scoped authorization. Option D is wrong because shared secrets with HMAC provide message integrity and authentication but do not offer a standardized way to enforce fine-grained authorization scopes; managing shared secrets at scale is also a security risk.

59
MCQeasy

A cloud security engineer is reviewing the security posture of a web application deployed on AWS. The application uses an Application Load Balancer (ALB) and EC2 instances. The engineer wants to ensure that all incoming traffic is encrypted in transit. Which action should the engineer take?

A.Use AWS Shield Advanced to protect the application from DDoS attacks.
B.Enable encryption at rest on the EC2 instance volumes using AWS KMS.
C.Configure a security group on the EC2 instances to allow only HTTPS traffic from the ALB.
D.Configure the ALB to use an HTTPS listener with an ACM certificate and redirect HTTP to HTTPS.
AnswerD

Configuring the ALB with an HTTPS listener using an AWS Certificate Manager (ACM) certificate encrypts traffic between clients and the ALB. Redirecting HTTP to HTTPS ensures that all incoming traffic uses TLS. This is the standard method to enforce encryption in transit for web applications behind an ALB, providing confidentiality and integrity for data in transit.

Why this answer

To encrypt incoming traffic, the Application Load Balancer must terminate TLS using an HTTPS listener with a valid certificate from AWS Certificate Manager. Redirecting HTTP to HTTPS ensures all clients use encryption. This secures data in transit from clients to the ALB, meeting the requirement.

Exam trap

The trap here is confusing encryption in transit with encryption at rest or network access controls, leading to selection of irrelevant measures like EBS encryption or security groups.

60
Multi-Selectmedium

A cloud application team is adopting a DevSecOps pipeline for a containerized workload. They want to integrate security testing that can detect vulnerable dependencies and misconfigured infrastructure-as-code templates before deployment. Which two practices should be implemented to meet these goals? (Choose two.)

Select 2 answers
A.Perform dynamic application security testing against the staging environment after each deployment to find runtime vulnerabilities.
B.Scan infrastructure-as-code templates with a policy-as-code tool that evaluates them against organizational security baselines and blocks noncompliant changes.
C.Enable runtime application self-protection in production to block exploitation attempts against the running application.
D.Deploy a web application firewall in front of the application and tune it using production traffic logs.
E.Run software composition analysis (SCA) against the application's dependency manifest during the build stage and fail the build on critical findings.
AnswersB, E

Policy-as-code scanning of IaC templates catches misconfigurations such as public storage buckets or overly permissive security groups before resources are created. Blocking noncompliant changes enforces the baseline. This satisfies the misconfiguration detection requirement and operates early in the pipeline, preventing drift and reducing remediation cost.

Why this answer

Detecting vulnerable dependencies requires software composition analysis of dependency manifests during the build. Detecting misconfigured IaC requires policy-as-code scanning of templates before deployment. Both are preventive and shift security left.

Runtime controls such as RASP and WAF, and dynamic testing of a running app, do not analyze dependencies or templates, so they do not meet the stated goals.

Exam trap

The trap here is treating runtime defenses such as RASP or WAF as substitutes for build-time dependency and IaC scanning, when they operate at a different stage and on different artifacts.

61
MCQhard

A security engineer is investigating an incident where an attacker exploited a server-side request forgery (SSRF) vulnerability in a cloud application. The application runs in a cloud environment and uses internal metadata endpoints. Which mitigation should be prioritized to prevent future SSRF attacks?

A.Implement input validation to block malicious URLs
B.Restrict outbound network access from the application instances using network security controls
C.Deploy a web application firewall (WAF) to inspect outgoing requests
D.Require token-based authentication for metadata service access
AnswerB

SSRF abuses the application's ability to make outbound requests, so restricting egress with network security controls prevents instances from reaching internal metadata endpoints such as 169.254.169.254. This directly addresses the cloud metadata exposure described in the stem.

Why this answer

Restricting outbound network access from application instances using security groups directly prevents the application from reaching internal metadata endpoints and other internal services. This is a fundamental network-layer control that stops SSRF attacks at the source, regardless of input validation or request inspection, by blocking the outbound traffic that the attacker would exploit.

Exam trap

ISC2 often tests the misconception that input validation or WAFs are sufficient to stop SSRF, when in reality the most effective mitigation is network-layer egress filtering that blocks access to internal metadata endpoints.

How to eliminate wrong answers

Option A is wrong because input validation to block malicious URLs is easily bypassed by attackers using URL encoding, redirects, or alternative representations of the metadata endpoint (e.g., decimal IP, DNS rebinding), and it does not address the root cause of the application making unauthorized outbound requests. Option C is wrong because a web application firewall (WAF) inspects incoming HTTP requests, not outgoing requests from the application; it cannot block the outbound SSRF traffic that originates from the application server itself. Option D is wrong because disabling IMDSv1 and requiring IMDSv2 tokens only protects the metadata service from unauthorized access via token-based authentication, but it does not prevent the application from making SSRF requests to other internal endpoints or external systems; the attacker could still exploit the application to make outbound requests to arbitrary targets.

62
Drag & Dropmedium

Drag and drop the steps for conducting a cloud security risk assessment using the NIST CSF framework into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Start with identification, then threat/vulnerability assessment, risk analysis, treatment, and monitoring.

63
MCQhard

An AWS S3 bucket policy is configured as shown in the exhibit. The security team wants to ensure that only requests from the corporate IP range (203.0.113.0/24) can read objects in the bucket. However, they notice that a CloudFront distribution configured to serve content from this bucket is returning 403 Forbidden errors. What is the MOST likely cause?

A.The bucket policy has a syntax error in the Condition block.
B.There is an implicit deny that overrides the explicit allow.
C.The bucket policy does not allow the s3:GetObject action.
D.CloudFront requests originate from CloudFront IP addresses, not the end user's IP.
AnswerD

CloudFront fetches objects from the bucket using its own edge IP addresses, so the bucket policy's 203.0.113.0/24 condition fails and returns 403. CloudFront must instead be granted access via an origin access identity or origin access control.

Why this answer

D is correct because when CloudFront fetches objects from an S3 origin, it uses its own IP addresses, not the end user's IP address. The bucket policy restricts access to the corporate IP range (203.0.113.0/24), but CloudFront's requests come from AWS's CloudFront edge IP range, which falls outside that range. This causes S3 to deny the request, resulting in a 403 Forbidden error.

Exam trap

ISC2 often tests the misconception that the end user's IP address is preserved through a CDN or proxy, leading candidates to incorrectly assume the bucket policy's IP restriction will work as intended.

How to eliminate wrong answers

Option A is wrong because the Condition block syntax is valid; the policy uses standard AWS IAM policy language with IpAddress condition key, and there is no syntax error indicated. Option B is wrong because there is no implicit deny overriding the explicit allow; the issue is that the condition does not match CloudFront's source IP, not a deny override. Option C is wrong because the policy explicitly allows the s3:GetObject action for the specified IP range, so the action is permitted when the condition is met.

64
MCQmedium

A software company develops an API for third-party integrations. They want to ensure that only authorized partners can access the API. Which authentication mechanism is most appropriate?

A.Basic authentication with API keys
B.OAuth 2.0 with client credentials
C.SAML 2.0
D.X.509 certificates
AnswerB

OAuth 2.0 client credentials issues tokens to confidential clients authenticating with their own credentials, without user involvement. This suits machine-to-machine partner integrations, satisfying the requirement that only authorised partners access the API and enabling scoped, revocable access.

Why this answer

OAuth 2.0 with the client credentials grant is the most appropriate mechanism for machine-to-machine API access because it allows the API to authenticate the third-party application itself (the client) using a client ID and client secret, without involving end-user credentials. This grant type is specifically designed for server-to-server integrations where the client is acting on its own behalf, providing a secure, token-based approach that avoids sharing long-lived secrets directly with each API call.

Exam trap

ISC2 often tests the distinction between authentication mechanisms by presenting SAML 2.0 as a plausible answer for API security, but the trap here is that SAML is designed for browser-based user authentication and federation, not for direct API access from third-party applications, leading candidates to confuse identity federation with API authorization.

How to eliminate wrong answers

Option A is wrong because Basic authentication with API keys transmits the API key in plaintext (Base64-encoded) with every request, offering no cryptographic protection and requiring the API key to be stored and sent repeatedly, which increases exposure risk and lacks the token expiration and scoping capabilities of OAuth 2.0. Option C is wrong because SAML 2.0 is an XML-based federated identity protocol designed for browser-based single sign-on (SSO) with user authentication, not for direct API access from third-party applications; it is heavy, not optimized for RESTful APIs, and does not provide a simple client credentials flow. Option D is wrong because X.509 certificates are used for mutual TLS (mTLS) authentication, which is more complex to manage (certificate issuance, renewal, revocation) and is typically reserved for high-security environments or regulatory compliance, not as a standard mechanism for third-party API integrations where OAuth 2.0 is the industry norm.

65
MCQeasy

A cloud team is designing a new microservices application deployed on a managed Kubernetes service. The security architect requires that all service-to-service traffic be encrypted with mutual TLS (mTLS) without modifying application code. Which cloud-native component should be implemented to meet this requirement?

A.An API gateway with TLS termination at the ingress
B.Kubernetes NetworkPolicy objects with default deny rules
C.A service mesh such as Istio or Linkerd
D.A web application firewall (WAF) in front of each service
AnswerC

A service mesh injects sidecar proxies that transparently intercept and encrypt traffic between services using mTLS, satisfying the no-code-change requirement. It also provides identity-based authentication and authorization. This is the standard cloud-native approach for zero-trust service communication in Kubernetes environments, and it operates at the platform layer rather than within the application.

Why this answer

A service mesh is the correct cloud-native solution because it provides transparent mTLS between services through sidecar proxies, requiring no application code changes. It also enables fine-grained authorization and observability. Other options address perimeter security or network segmentation but do not deliver encrypted, mutually authenticated service-to-service communication inside the cluster.

Exam trap

The trap here is assuming that a WAF or API gateway provides internal service-to-service encryption, when they only protect traffic at the perimeter or ingress.

66
MCQhard

An organization uses a multi-cloud architecture with applications running on both AWS and Azure. They need to implement a secrets management solution that works across both platforms and supports automated rotation. Which approach best meets these requirements?

A.Deploy HashiCorp Vault as a centralized secrets manager
B.Store secrets as encrypted environment variables in each environment
C.Use Azure Key Vault with a federation bridge to AWS
D.Use AWS Secrets Manager for all secrets
AnswerA

HashiCorp Vault runs platform-agnostically, so a single control plane issues and rotates secrets for both AWS and Azure workloads. Its dynamic secrets engines and API-driven rotation satisfy the cross-platform and automated rotation constraints that native AWS Secrets Manager or Azure Key Vault cannot meet alone.

Why this answer

HashiCorp Vault is a platform-agnostic secrets management solution that runs on any cloud or on-premises environment, supports dynamic secrets, and provides automated secret rotation via leases and rotation policies. It is the only option that natively spans AWS and Azure with consistent APIs and automated rotation.

Exam trap

The trap is assuming a single-cloud native service (AWS Secrets Manager or Azure Key Vault) can manage secrets across both clouds — only a cloud-agnostic tool like Vault natively satisfies multi-cloud rotation.

How to eliminate wrong answers

Option B is wrong because encrypted environment variables are static, platform-specific, and lack automated rotation or centralized audit — they do not meet the multi-cloud rotation requirement. Option C is wrong because Azure Key Vault is Azure-native and does not natively manage AWS secrets; a 'federation bridge' is not a standard product feature and would require custom integration. Option D is wrong because AWS Secrets Manager is AWS-native and cannot manage secrets for Azure workloads without custom cross-cloud plumbing, and its rotation Lambdas are AWS-specific.

67
MCQmedium

A media company uses a CI/CD pipeline to deploy a web application to a cloud platform. The security team wants to integrate security testing that can detect vulnerabilities in third-party libraries and base images before deployment, without significantly slowing the pipeline. Which practice should be implemented?

A.Static application security testing (SAST) on the application source code only.
B.Software composition analysis (SCA) and container image scanning integrated into the pipeline.
C.Dynamic application security testing (DAST) against the staging environment after each deployment.
D.Interactive application security testing (IAST) with agents in the staging environment.
AnswerB

SCA examines dependency manifests and lockfiles to identify known vulnerabilities in third-party libraries, while container image scanning inspects image layers for vulnerable packages and misconfigurations. Both run early in the pipeline, provide fast feedback, and can fail builds on policy violations, meeting the requirement to detect issues before deployment without heavy slowdown.

Why this answer

Detecting vulnerabilities in third-party libraries and base images before deployment requires tools that inspect dependencies and image contents. SCA reads dependency manifests for known CVEs, and container image scanning checks layers for vulnerable packages. Both integrate into CI/CD with fast, automated feedback.

DAST and IAST need running environments and target runtime behavior, while SAST covers only first-party code, so none of those alone meets the requirement.

Exam trap

The trap here is assuming that any security testing in CI/CD covers third-party libraries and base images, when each tool type has a distinct scope.

68
MCQmedium

A company runs a multi-tier cloud application with a web frontend, an API layer, and a database. The application uses OAuth 2.0 for authentication. Recently, users have been experiencing session hijacking attacks. Upon investigation, the security team finds that session tokens are being intercepted in transit. The application uses HTTPS for all communications, but a developer discovers that the application is also accessible via HTTP due to a misconfiguration. The team wants to implement additional security controls to prevent token theft. Which course of action should be taken first?

A.Use IP address binding for session tokens
B.Implement HTTP Strict Transport Security (HSTS) to enforce HTTPS connections
C.Switch from OAuth to SAML for authentication
D.Shorten the session token expiration time
AnswerB

HSTS forces browsers to use HTTPS exclusively for the domain, eliminating the HTTP misconfiguration that exposes tokens to interception. Addressing the transport downgrade first satisfies the requirement to prevent token theft, since encrypted delivery removes the interception vector.

Why this answer

The root cause is that the application is accessible via HTTP due to a misconfiguration, allowing session tokens to be intercepted in transit despite HTTPS being available. Implementing HTTP Strict Transport Security (HSTS) forces the browser to always use HTTPS, preventing any HTTP connections and thus eliminating the interception vector. This directly addresses the misconfiguration before other controls, which would only mitigate but not prevent the theft.

Exam trap

ISC2 often tests the concept that session hijacking prevention must address the root cause (insecure transport) rather than just mitigating the impact of token theft, leading candidates to choose options like shortening expiration or IP binding instead of enforcing HTTPS with HSTS.

How to eliminate wrong answers

Option A is wrong because IP address binding for session tokens is a server-side binding that can help prevent token reuse from different IPs, but it does not prevent the initial interception of the token over HTTP; the token can still be stolen in transit. Option C is wrong because switching from OAuth 2.0 to SAML does not change the transport security issue; both protocols can be used over HTTP and are equally vulnerable to interception if HTTPS is not enforced. Option D is wrong because shortening the session token expiration time reduces the window of opportunity for an attacker to use a stolen token, but it does not prevent the token from being intercepted in the first place over an HTTP connection.

69
MCQmedium

A security team is implementing a web application firewall (WAF) for a cloud-based e-commerce application. The application is built on a microservices architecture and uses a RESTful API. Which of the following is the PRIMARY reason to deploy the WAF at the API gateway level rather than at the individual service level?

A.To provide centralized protection against common web exploits before traffic reaches the microservices.
B.To reduce latency by caching responses at the API gateway.
C.To offload authentication from the microservices to the API gateway.
D.To monitor API usage and detect anomalies in traffic patterns.
AnswerA

Placing the WAF at the API gateway filters malicious traffic once, before it is routed to any microservice, giving centralised coverage of common exploits such as SQL injection and cross-site scripting. This satisfies the microservices constraint, avoiding duplicated per-service rule management.

Why this answer

Deploying the WAF at the API gateway provides a centralized security enforcement point that inspects and filters all incoming HTTP/HTTPS traffic before it is routed to any individual microservice. This ensures that common web exploits—such as SQL injection, cross-site scripting (XSS), and OWASP Top 10 attacks—are blocked at the perimeter, reducing the attack surface and preventing malicious payloads from ever reaching the internal services. It also simplifies policy management and avoids the need to configure and maintain separate WAF instances for each microservice, which would introduce operational complexity and potential gaps in coverage.

Exam trap

The trap here is that candidates confuse the WAF's primary security purpose (centralized exploit prevention) with other common API gateway features like caching, authentication offloading, or traffic monitoring, leading them to select a technically valid but non-primary reason for WAF placement.

How to eliminate wrong answers

Option B is wrong because caching responses at the API gateway is a performance optimization, not a primary security reason for deploying a WAF; WAFs do not inherently cache responses, and caching is typically handled by a separate reverse proxy or CDN. Option C is wrong because offloading authentication to the API gateway is an identity and access management function, not a WAF function; while an API gateway can handle authentication, a WAF's primary role is to inspect and filter traffic for malicious content, not to authenticate users. Option D is wrong because monitoring API usage and detecting anomalies in traffic patterns is typically the responsibility of an API management platform or a dedicated security analytics tool, not the core function of a WAF; a WAF focuses on blocking known attack signatures and behavioral anomalies, but its primary deployment reason is centralized threat protection, not monitoring alone.

70
MCQeasy

A cloud application uses a RESTful API that handles payment transactions. The security team identifies that the API is vulnerable to brute-force attacks on the authentication endpoint. Which control should be implemented to mitigate this?

A.Implement rate limiting on the authentication endpoint
B.Require API keys for all requests
C.Use TLS to encrypt the communication channel
D.Add input validation for all parameters
AnswerA

Rate limiting caps the number of authentication attempts from a given source within a time window, throttling the repeated credential guesses that define brute-force attacks. This directly addresses the stem's identified vulnerability on the authentication endpoint.

Why this answer

Rate limiting restricts the number of authentication requests from a single source within a given time window, directly mitigating brute-force attacks by making it infeasible to guess credentials at high speed. This control is specifically designed for authentication endpoints where repeated failed attempts are the primary attack vector, and it is a standard recommendation in OWASP and NIST guidelines for API security.

Exam trap

ISC2 often tests the distinction between authentication-specific controls (rate limiting) and general security measures (encryption, input validation), leading candidates to choose TLS or API keys because they are commonly associated with API security but do not address brute-force frequency.

How to eliminate wrong answers

Option B is wrong because API keys authenticate the client application, not the user, and do not prevent an attacker from repeatedly trying different passwords or tokens against the authentication endpoint. Option C is wrong because TLS encrypts data in transit to prevent eavesdropping and tampering, but it does not limit the number of requests an attacker can send, leaving the endpoint vulnerable to brute-force attempts. Option D is wrong because input validation prevents injection attacks (e.g., SQLi, XSS) but does not restrict the frequency of requests, so an attacker can still submit unlimited login attempts with valid parameter formats.

71
MCQhard

A cloud security architect is designing a CI/CD pipeline for a serverless application using AWS Lambda. The application processes sensitive user data and requires encryption at rest and in transit. Which of the following is the BEST approach to securely manage database credentials used by the Lambda function?

A.Store the credentials in AWS Systems Manager Parameter Store with a SecureString parameter.
B.Use AWS Secrets Manager to store the credentials and retrieve them at runtime with least-privilege IAM roles.
C.Store the credentials as encrypted environment variables in the Lambda function configuration.
D.Hardcode the credentials in the Lambda function code and encrypt the deployment package.
AnswerB

Secrets Manager stores credentials outside the function code and rotates them, while runtime retrieval via least-privilege IAM roles avoids hard-coded secrets. This satisfies the encryption and sensitive-data constraints without embedding credentials in Lambda environment variables or code.

Why this answer

AWS Secrets Manager is the best choice because it is purpose-built for securely storing, rotating, and retrieving secrets such as database credentials. It integrates natively with AWS Lambda via the Secrets Manager API, allowing the function to fetch credentials at runtime using a least-privilege IAM role. This approach avoids embedding secrets in code or configuration and supports automatic rotation, which is critical for compliance with encryption and access control requirements.

Exam trap

ISC2 often tests the distinction between AWS Systems Manager Parameter Store (for configuration) and AWS Secrets Manager (for secrets), trapping candidates who think encryption alone is sufficient without considering rotation and lifecycle management.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store with SecureString provides encryption but lacks native automatic rotation and fine-grained access control for secrets; it is designed for configuration data, not secrets management. Option C is wrong because encrypted environment variables are still stored in the Lambda configuration and can be exposed through logs, error messages, or the AWS Management Console; they also do not support rotation. Option D is wrong because hardcoding credentials in code, even with an encrypted deployment package, violates the principle of not embedding secrets in code and makes rotation impossible without redeployment; the encryption key management also adds unnecessary complexity.

72
Multi-Selectmedium

Which TWO practices help protect against insecure deserialization attacks in cloud applications?

Select 2 answers
A.Allow deserialization from untrusted sources
B.Use strong encryption for all serialized data
C.Implement custom deserialization without validation
D.Validate serialized objects before deserialization
E.Restrict deserialization to a whitelist of classes
AnswersD, E

Validating serialised objects before deserialisation rejects unexpected classes and malformed payloads, preventing gadget chains from executing during object reconstruction. This satisfies the stem's requirement for a practise that protects cloud applications against insecure deserialisation attacks.

Why this answer

Option D is correct because validating serialized objects before deserialization ensures that the data being processed matches expected types, structures, and values, which prevents attackers from injecting malicious payloads that exploit deserialization logic. Option E is correct because restricting deserialization to a whitelist of allowed classes ensures that only pre-approved, safe classes can be instantiated, blocking gadget-chain attacks that rely on unexpected or dangerous classes. Option A is incorrect because allowing deserialization from untrusted sources directly enables insecure deserialization attacks.

Option B is incorrect because strong encryption protects data confidentiality in transit or at rest but does not prevent malicious payloads from being deserialized after decryption. Option C is incorrect because implementing custom deserialization without validation removes the safety checks needed to reject malicious or unexpected objects.

Exam trap

ISC2 often tests the misconception that encryption alone (Option B) is sufficient to secure serialized data, but encryption only protects data at rest or in transit, not the deserialization process itself, which is where the attack occurs.

73
Multi-Selectmedium

Which TWO of the following are primary objectives of a cloud application security program?

Select 2 answers
A.Maintaining application availability
B.Performing continuous deployment
C.Implementing a microservices architecture
D.Ensuring data confidentiality and integrity
E.Adopting Agile development practices
AnswersA, D

Availability is a core security objective because a cloud application rendered unreachable effectively fails its security posture. Resilience, redundancy and DDoS mitigation preserve service continuity, satisfying the program's mandate to keep applications accessible to legitimate users.

Why this answer

Option A (Maintaining application availability) is correct because a cloud application security program must protect against denial-of-service, misconfiguration, and resilience failures so that applications remain accessible to authorized users, aligning with the availability pillar of the CIA triad. Option D (Ensuring data confidentiality and integrity) is correct because the core purpose of application security is to prevent unauthorized disclosure and unauthorized modification of data, typically enforced through encryption, access controls, and integrity checks. Options B (continuous deployment), C (microservices architecture), and E (Agile development practices) are incorrect because they are software delivery and architectural methodologies, not security objectives; they may support security when implemented well but are not primary goals of a cloud application security program.

Exam trap

ISC2 often tests the distinction between security objectives and operational or architectural practices, trapping candidates who confuse 'continuous deployment' or 'microservices' with security goals because they are commonly discussed in cloud security contexts but are not primary objectives.

74
MCQhard

A cloud application uses containers orchestrated by Kubernetes. The security team wants to enforce that containers cannot run as root and that file systems are read-only at runtime. Which Kubernetes security context configuration should be applied?

A.Use a RuntimeClass that disables root capabilities
B.Set the container's user to a non-root user in the Dockerfile
C.Apply a PodSecurityPolicy that blocks privileged containers
D.Configure a SecurityContext with runAsNonRoot: true and readOnlyRootFilesystem: true
AnswerD

SecurityContext fields runAsNonRoot and readOnlyRootFilesystem directly enforce the two stated constraints: the container process cannot run as UID 0, and its root filesystem is mounted read-only, blocking runtime writes. Pod Security Admission alone would not guarantee both.

Why this answer

Kubernetes SecurityContext allows fine-grained control over container permissions at the pod or container level. Setting `runAsNonRoot: true` ensures the container cannot run as UID 0, and `readOnlyRootFilesystem: true` mounts the container's root filesystem as read-only, preventing unauthorized writes at runtime. This directly satisfies the security team's requirements without relying on external policies or image-level configurations.

Exam trap

The trap here is that candidates confuse image-level defaults (like a non-root user in a Dockerfile) with runtime enforcement via SecurityContext, or they think PodSecurityPolicy (a deprecated feature) is the only way to enforce these restrictions, when in fact SecurityContext is the direct and correct mechanism.

How to eliminate wrong answers

Option A is wrong because a RuntimeClass primarily selects a container runtime (e.g., gVisor, Kata Containers) for isolation, not a mechanism to disable root capabilities or enforce read-only filesystems; it does not directly set runAsNonRoot or readOnlyRootFilesystem. Option B is wrong because setting a non-root user in the Dockerfile only affects the image's default user; it can be overridden at runtime (e.g., by specifying `securityContext.runAsUser: 0`), so it does not enforce the restriction. Option C is wrong because PodSecurityPolicy (PSP) is a deprecated, cluster-level admission controller that can block privileged containers but does not directly enforce `runAsNonRoot: true` or `readOnlyRootFilesystem: true`; it requires additional policy rules and is being replaced by Pod Security Standards.

75
Multi-Selecteasy

Which TWO of the following are secure coding practices that help prevent injection attacks?

Select 2 answers
A.Printing stack traces in production error messages
B.Using parameterized queries for database calls
C.Using stored procedures exclusively
D.Validating and sanitizing all user inputs
E.Storing user passwords in plaintext
AnswersB, D

Parameterised queries separate SQL code from user-supplied data, so the database engine treats input strictly as values rather than executable statements. This structurally prevents injection by ensuring untrusted data cannot alter query logic, directly satisfying the stem's requirement for a secure coding practise that mitigates injection attacks.

Why this answer

Option B is correct because parameterized queries (prepared statements) separate SQL code from user-supplied data, so the database engine treats input as data rather than executable SQL, which neutralizes SQL injection. Option D is correct because validating and sanitizing all user inputs enforces expected formats and strips or escapes dangerous characters, reducing the attack surface for SQL, command, and other injection attacks. Option A is incorrect because printing stack traces in production leaks internal details such as file paths, query fragments, and framework versions that aid attackers, and it does nothing to prevent injection.

Option C is incorrect because stored procedures are not inherently safe—if they build dynamic SQL by concatenating user input, they remain vulnerable to injection, so they are not a guaranteed secure coding practice. Option E is incorrect because storing passwords in plaintext is a severe confidentiality failure that enables credential theft and has no bearing on preventing injection attacks.

Exam trap

ISC2 often tests the misconception that stored procedures are inherently safe against injection, but the trap is that stored procedures can still be vulnerable if they dynamically construct SQL strings using concatenated input, so parameterization must be applied inside the procedure as well.

Page 1 of 2 · 114 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cloud App Security questions.