Courseiva

CCSP · topic practice

Cloud Application Security practice questions

Cloud Application Security covers securing the software development lifecycle, APIs, identity, and runtime workloads in cloud environments. CCSP tests this through scenario questions on authentication choices, secrets management, serverless and container hardening, secure SDLC practices, and the shared responsibility boundary between provider-managed services and customer-implemented controls.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Cloud Application Security

What the exam tests

What to know about Cloud Application Security

A candidate must choose the right authentication and secrets-management mechanism for a given cloud workload and apply least privilege to serverless and container identities. The single most important thing is matching the control to the threat: use OAuth 2.0 for third-party API access and a managed secrets service for rotating credentials.

Selecting OAuth 2.0, OpenID Connect, or SAML for API and partner authentication versus static API keys

Using AWS Secrets Manager, Azure Key Vault, or HashiCorp Vault for credential storage and rotation

Applying IAM roles and resource policies to scope AWS Lambda execution permissions and S3 triggers

Securing API keys and tokens by avoiding URL query strings and enforcing TLS with header-based transmission

Watch out for

Common Cloud Application Security exam traps

  • ▸Assuming API keys provide sufficient authorization for partner access when OAuth 2.0 scopes and token expiry are required for delegated, revocable access.
  • ▸Embedding database credentials directly in container images or environment variables instead of using a managed secrets store with automatic rotation.
  • ▸Granting Lambda functions broad wildcard IAM permissions rather than least-privilege roles scoped to specific S3 buckets and actions.

Practice set

Cloud Application Security questions

20 questions · select your answer, then reveal the explanation

A cloud application uses a third-party identity provider (IdP) for SSO. The security team notices that tokens are being reused across different applications. Which token binding mechanism should be implemented?

Refer to the exhibit. A security administrator is reviewing an S3 bucket policy. What is the primary security concern with this policy?

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:PutObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "203.0.113.0/24"
        }
      }
    }
  ]
}
```

Refer to the exhibit. A Kubernetes pod is configured as shown. Which security enhancement should be added to follow cloud security best practices?

Exhibit

Refer to the exhibit.

```
apiVersion: v1
kind: Pod
metadata:
  name: web-app
spec:
  containers:
  - name: web
    image: nginx:latest
    securityContext:
      runAsUser: 1000
      runAsGroup: 3000
      allowPrivilegeEscalation: false
    ports:
    - containerPort: 80
```

A cloud application developer is using a containerized application with Docker. The security team requires that the application runs with the least privilege possible. Which of the following is the BEST practice to ensure the container does not run as root?

Which THREE of the following are essential components of a Secure Software Development Lifecycle (SSDLC) for cloud applications?

You are a cloud security engineer for a financial services company. The company has developed a cloud-native application that processes credit card transactions and stores sensitive financial data. The application is deployed on a Kubernetes cluster in a public cloud provider. The compliance team requires that all data at rest be encrypted using a customer-managed key (CMK) with automatic rotation. The application uses a managed database service (e.g., Amazon RDS) and object storage (e.g., Amazon S3) for storing transaction logs. The current configuration uses cloud-provider-managed keys for both services. The development team is concerned that enabling CMK with automatic rotation might cause application downtime due to key rotation latency. Additionally, the security team wants to ensure that access to the keys is auditable. Which course of action BEST addresses the compliance requirement while minimizing risk?

Refer to the exhibit. A security analyst reviews the S3 bucket policy shown. Which security issue should be flagged?

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::123456789012:role/MyAppRole"
      },
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-bucket/*"
    },
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::my-bucket/uploads/*"
    }
  ]
}
```

Drag and drop the steps for implementing a cloud data encryption strategy using a customer-managed key (CMK) in AWS KMS into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each cloud service model to its primary responsibility area according to the shared responsibility model.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Application security

Platform security

Infrastructure security

Full stack security

Match each compliance framework to its primary jurisdiction or industry.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

European Union data protection

US healthcare information privacy

Payment card industry security

US financial reporting controls

A developer is writing code that will be deployed as a serverless function. The function needs to read data from a cloud storage bucket. According to the principle of least privilege, how should the developer grant access?

A cloud security engineer is configuring a cloud function that processes messages from a message queue service. The function needs to write results to a NoSQL database. Which of the following is the SECUREST way to manage the function's credentials?

A developer is implementing a cloud application that stores sensitive user data. To minimize the risk of data exposure during transit, which security control should be enforced as a baseline requirement?

A cloud application is being designed to handle highly sensitive financial data. The security architect wants to ensure that encryption keys are managed outside the application's memory space. Which service model should they use?

During a security audit, a cloud application is found to have numerous container images with critical vulnerabilities. The DevOps team wants to prevent vulnerable images from being deployed to production. Which two controls should be implemented? (Select TWO)

A cloud application processes data subject to GDPR. The security team needs to ensure that all personally identifiable information (PII) is encrypted at rest and that access is logged. Which combination of controls should be implemented? (Select THREE)

Question 17mediummultiple choice
Review the full routing breakdown →

A developer receives the above error when trying to create a route in an API Gateway. Which action should the developer take to resolve the issue?

Exhibit

Refer to the exhibit.

Exhibit:

Error: Error creating API Gateway v2: BadRequestException: Failed to create route because the requested route key is already in use
	status code: 400, request id: c6a1b2c3-d4e5-f6a7-b8c9-d0e1f2a3b4c5

Cause: The route key '/api/orders' already exists in the API.

A security analyst reviews the above cloud storage bucket policy. The bucket stores sensitive application data. What is the primary security issue with this policy?

Exhibit

Refer to the exhibit.

Exhibit:

JSON Policy (AWS S3 bucket policy):
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::myapp-data/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "10.0.0.0/8"
        }
      }
    },
    {
      "Effect": "Deny",
      "Principal": "*",
      "Action": "s3:*",
      "Resource": "arn:aws:s3:::myapp-data/*"
    }
  ]
}

A security analyst is reviewing cloud audit logs and sees the above event. The analyst suspects that the machine image used may be outdated and vulnerable. Which action should the analyst take to verify the security posture of the launched instance?

Exhibit

Refer to the exhibit.

Exhibit:

CloudTrail log (JSON):
{
  "eventVersion": "1.08",
  "userIdentity": {
    "type": "IAMUser",
    "arn": "arn:aws:iam::123456789012:user/app-admin",
    "accountId": "123456789012"
  },
  "eventSource": "ec2.amazonaws.com",
  "eventName": "RunInstances",
  "resources": [
    {
      "resourceType": "AWS::EC2::Instance",
      "resourceName": "i-0abcdef1234567890"
    }
  ],
  "userAgent": "console.amazonaws.com",
  "sourceIPAddress": "203.0.113.50",
  "responseElements": {
    "instancesSet": {
      "items": [
        {
          "instanceId": "i-0abcdef1234567890",
          "imageId": "ami-0c55b159cbfafe1f0"
        }
      ]
    }
  }
}

A security auditor is reviewing a cloud application's data encryption strategy. The application stores sensitive data in a cloud database. Which configuration would best ensure data confidentiality in the event of a database dump?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cloud Application Security sessions

Start a Cloud Application Security only practice session

Every question in these sessions is drawn from the Cloud Application Security domain — nothing else.

Related practice questions

Related CCSP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CCSP exam test about Cloud Application Security?
A candidate must choose the right authentication and secrets-management mechanism for a given cloud workload and apply least privilege to serverless and container identities. The single most important thing is matching the control to the threat: use OAuth 2.0 for third-party API access and a managed secrets service for rotating credentials.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cloud Application Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Cloud Application Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CCSP topics?
Use the topic links above to move to related areas, or go back to the CCSP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CCSP exam covers. They are not copied from any real exam or dump site.