Courseiva

CCNA Cloud App Security Questions

39 of 114 questions · Page 2/2 · Cloud App Security topic · Answers revealed

76
MCQeasy

A retail company migrates its customer-facing web application to a cloud environment. The security team wants to ensure that security testing is integrated throughout the software development lifecycle (SDLC) rather than only before production deployment. Which approach best aligns with this goal?

A.Adopt a DevSecOps approach with automated security testing in the CI/CD pipeline.
B.Implement security gates at the end of each development sprint.
C.Require developers to complete annual secure coding training.
D.Conduct a penetration test after the application is deployed to production.
AnswerA

A DevSecOps approach integrates security automatically into every stage of the CI/CD pipeline, enabling early detection and remediation of vulnerabilities. This aligns with the goal of continuous security testing throughout the SDLC. Automated tools like SAST, DAST, and dependency scanning run with each build, providing rapid feedback to developers. This reduces risk and cost compared to late-stage testing, and fosters a security-first culture.

Why this answer

Integrating security testing into the CI/CD pipeline through a DevSecOps approach ensures that vulnerabilities are identified and addressed continuously as code is developed and deployed. This shifts security left, reduces remediation costs, and aligns with modern cloud application security best practices. Other options either delay testing or rely solely on human training, which does not provide the continuous automated assurance required.

Exam trap

The trap here is assuming that periodic security gates or annual training are sufficient for continuous security, when the goal requires automated, integrated testing throughout the SDLC.

77
MCQeasy

A cloud security architect is designing a multi-tier application that processes sensitive customer data. To protect data in transit between the web tier and the application tier, which of the following is the MOST appropriate approach?

A.Use standard TLS with server-side certificates only
B.Establish SSH tunnels for all inter-tier communication
C.Use mutual TLS (mTLS) between the tiers
D.Implement IPsec VPN between the tiers
AnswerC

Mutual TLS authenticates both the web tier and application tier with certificates and encrypts the channel between them, so neither side accepts an impostor. This satisfies the requirement to protect sensitive customer data in transit between those specific tiers.

Why this answer

Mutual TLS (mTLS) is the most appropriate approach because it provides bidirectional authentication and encryption between the web tier and application tier. In a multi-tier application processing sensitive customer data, mTLS ensures that both the client (web tier) and server (application tier) present valid certificates, preventing man-in-the-middle attacks and unauthorized inter-tier communication. This is critical for protecting data in transit in zero-trust or internal network segments where simple server-side TLS would not verify the identity of the calling service.

Exam trap

ISC2 often tests the misconception that standard TLS (server-side only) is sufficient for internal service-to-service communication, but the trap here is that without mutual authentication, an attacker who compromises the web tier could impersonate it to the application tier, or a rogue service could connect to the application tier undetected.

How to eliminate wrong answers

Option A is wrong because standard TLS with server-side certificates only authenticates the server to the client, but does not authenticate the client (web tier) to the application tier, leaving the application tier vulnerable to unauthorized or spoofed connections. Option B is wrong because SSH tunnels provide point-to-point encryption but are designed for interactive shell access or port forwarding, not for high-throughput, persistent inter-tier service communication; they introduce management overhead and lack the certificate-based identity verification that mTLS offers for service-to-service authentication. Option D is wrong because IPsec VPN operates at the network layer and encrypts all traffic between subnets, but it is overly complex for application-layer communication, adds latency, and does not provide application-level identity verification between specific services; it is more suited for site-to-site connectivity rather than fine-grained inter-tier authentication.

78
MCQeasy

An organization is developing a mobile app that communicates with a cloud API. To ensure secure authentication, which of the following should be used?

A.Session cookies for state management
B.Basic authentication with username and password
C.OAuth 2.0 with OpenID Connect
D.API keys sent in HTTP headers
AnswerC

OAuth 2.0 supplies delegated authorisation tokens, while OpenID Connect adds an identity layer with a signed ID token, letting the app verify the end user. This satisfies the secure authentication requirement that plain OAuth 2.0 alone cannot provide.

Why this answer

OAuth 2.0 with OpenID Connect (OIDC) is the correct choice because it provides a delegated authorization framework (OAuth 2.0) combined with an identity layer (OIDC) that enables secure authentication and single sign-on (SSO) for mobile apps communicating with cloud APIs. This combination issues short-lived access tokens and ID tokens (typically JWTs) rather than exposing long-lived credentials, and supports token refresh, scoped permissions, and PKCE (Proof Key for Code Exchange) to prevent authorization code interception on mobile devices.

Exam trap

ISC2 often tests the misconception that API keys or Basic auth are sufficient for mobile-to-cloud authentication, but the trap is that these methods lack the delegation, token lifecycle management, and identity verification that OAuth 2.0 with OpenID Connect provides, which is the industry standard (RFC 6749, RFC 7519) for securing mobile API access.

How to eliminate wrong answers

Option A is wrong because session cookies are designed for server-side web applications with browser-based state management; mobile apps lack a browser context for cookie handling and are vulnerable to CSRF and session hijacking, making cookies unsuitable for native mobile-to-API communication. Option B is wrong because Basic authentication transmits credentials (Base64-encoded username:password) in every request, exposing them to interception and replay attacks; it offers no token expiration, no scoping, and no support for multi-factor authentication, violating cloud security best practices. Option D is wrong because API keys sent in HTTP headers are static, long-lived secrets that are easily leaked in client-side code (e.g., mobile app binaries), provide no user authentication or delegation, and lack built-in revocation mechanisms beyond key rotation.

79
MCQmedium

A security team is reviewing a cloud application's CI/CD pipeline. They want to ensure that only approved open-source libraries are used in production builds. Which approach best addresses this requirement?

A.Segment the build network to limit internet access
B.Perform static code analysis after each build
C.Implement a software composition analysis (SCA) tool in the pipeline
D.Require manual approval for all library updates
AnswerC

Software composition analysis inventories every open-source component and its transitive dependencies, then matches them against vulnerability and licence databases. Embedding SCA in the CI/CD pipeline enforces the approval constraint by failing builds that introduce unapproved libraries, giving the gate the stem requires before artefacts reach production.

Why this answer

A Software Composition Analysis (SCA) tool is specifically designed to automatically scan open-source libraries for known vulnerabilities, licensing issues, and version compliance. By integrating SCA into the CI/CD pipeline, the team can enforce a policy that only approved libraries (e.g., those passing a security and license review) are allowed in production builds, blocking unapproved or vulnerable components before deployment.

Exam trap

ISC2 often tests the distinction between SAST (static code analysis), DAST (dynamic analysis), and SCA, expecting candidates to recognize that only SCA directly addresses the management and approval of third-party open-source components and their associated risks.

How to eliminate wrong answers

Option A is wrong because segmenting the build network to limit internet access only restricts network connectivity, but does not prevent developers from introducing unapproved libraries already cached or stored locally; it also breaks legitimate dependency resolution from approved repositories. Option B is wrong because static code analysis (SAST) focuses on source code flaws (e.g., SQL injection, buffer overflows) and does not inspect third-party library metadata, licenses, or known CVEs in dependencies. Option D is wrong because requiring manual approval for all library updates is an operational process that does not scale, lacks automated detection of unapproved libraries, and introduces human error and delay without providing a technical enforcement gate in the pipeline.

80
MCQmedium

A healthcare SaaS company runs containerized microservices on Google Kubernetes Engine (GKE). The security team scans containers with a vulnerability scanner and finds that base images have several critical vulnerabilities. The container build process uses a Dockerfile that pulls the latest Ubuntu image from Docker Hub. The team wants to reduce the attack surface without delaying feature releases. What is the best approach?

A.Place a network security policy to restrict outbound traffic from pods
B.Schedule weekly automated rebuilds with the latest base image
C.Adopt minimal hardened base images and integrate vulnerability scanning into CI/CD
D.Refactor all applications to use scratch as base image
AnswerC

Minimal hardened base images strip unnecessary packages, shrinking the exploitable surface, while CI/CD scanning catches vulnerabilities before release rather than after. Together they satisfy the stem's constraint of reducing attack surface without delaying feature releases, unlike pinning tags alone.

Why this answer

Adopting minimal hardened base images (e.g., distroless, Alpine, or UBI-minimal) reduces the number of packages and thus the attack surface, while integrating vulnerability scanning into CI/CD catches issues early without slowing releases. This directly addresses the root cause—vulnerable base images—and provides continuous feedback. The other options either don't fix the base image problem or are too disruptive.

Exam trap

CCSP often tests the misconception that network controls or periodic rebuilds alone can mitigate image vulnerabilities, when the core issue is the base image and lack of continuous scanning.

How to eliminate wrong answers

Option A is wrong because network policies restrict traffic but do not remove vulnerabilities from container images. Option B is wrong because weekly rebuilds with the latest base image may still include vulnerable packages and do not guarantee a reduced attack surface; they also don't integrate scanning. Option D is wrong because refactoring all applications to use scratch as a base image is often impractical (e.g., requires static binaries, no shell) and would delay feature releases.

81
MCQeasy

A development team is building a cloud application that stores sensitive customer data in a managed database service. The security policy requires that data be encrypted at rest with keys that the organization controls and can rotate independently of the cloud provider. Which approach meets this requirement?

A.Encrypt sensitive columns at the application layer using a key derived from a static passphrase embedded in the source code.
B.Enable transparent data encryption on the database and store the master key in the application's configuration file.
C.Encrypt the database volume with a customer-managed key stored in the cloud provider's key management service, with key rotation and access policies defined by the organization.
D.Use the cloud provider's default service-managed encryption keys and enable automatic key rotation in the provider console.
AnswerC

Customer-managed keys in the provider's KMS give the organization control over key lifecycle, rotation, and access policies while integrating with the managed database. This satisfies both encryption at rest and independent key control. The organization can rotate, disable, or revoke keys and audit their use, meeting the policy requirement.

Why this answer

The requirement is encryption at rest with organizational control over keys. Customer-managed keys in the cloud KMS allow the organization to define rotation, access policies, and revocation while integrating with the managed database. Provider-managed keys, keys in config files, and passphrase-derived keys do not provide the required control and lifecycle management.

Exam trap

The trap here is equating encryption at rest with key control, when service-managed keys do not give the organization independent rotation and revocation authority.

82
MCQeasy

A cloud application uses OAuth 2.0 for authorization. What is the primary purpose of using a refresh token in this flow?

A.To obtain a new access token when the current one expires without user interaction.
B.To grant the same access token indefinitely.
C.To authenticate the user without a password.
D.To store user credentials on the resource server for later use.
AnswerA

A refresh token lets the client request a fresh access token from the authorisation server after expiry, avoiding repeated user consent. It satisfies the constraint of maintaining sessions without re-authentication while access tokens stay short-lived.

Why this answer

In OAuth 2.0, access tokens are short-lived by design to limit the window of compromise. A refresh token is a long-lived credential that allows the client to obtain a new access token from the authorization server without requiring the user to re-authenticate or re-consent. This enables seamless, ongoing access to protected resources while maintaining security through short-lived access tokens.

Exam trap

ISC2 often tests the misconception that refresh tokens are used for authentication or that they extend the life of the same access token, rather than understanding they are a separate credential used to obtain a new access token.

How to eliminate wrong answers

Option B is wrong because refresh tokens do not grant indefinite access; they can be revoked, have their own expiration, and are used to obtain new access tokens, not to extend the life of the same token. Option C is wrong because refresh tokens are not used for authentication; they are an authorization grant that assumes prior authentication has already occurred. Option D is wrong because refresh tokens are stored on the client (or client's backend), not on the resource server, and they are never used to store user credentials.

83
MCQhard

A cloud-native payroll application stores employee bank details in a managed database. The security team wants to ensure that even if the database storage is compromised, the data cannot be read without explicit decryption. They also need to minimize changes to the application code. Which approach best meets these requirements?

A.Use database-native column encryption with keys stored in the database configuration.
B.Enable transparent data encryption (TDE) at the database storage layer using provider-managed keys.
C.Implement client-side field-level encryption using a customer-managed key (CMK) in a cloud KMS.
D.Rely on the cloud provider's default encryption at rest with provider-managed keys.
AnswerC

Client-side field-level encryption encrypts sensitive fields before they reach the database, so stored ciphertext is useless without the CMK. Using a customer-managed key in a cloud KMS keeps key control with the organization and enables explicit decryption. The application performs encryption and decryption, which is a code change but targeted to specific fields, meeting both requirements.

Why this answer

The team needs encryption where keys are controlled by the organization and decryption is explicit, not automatic. Client-side field-level encryption with a customer-managed key in a cloud KMS achieves this: ciphertext is stored in the database, and only holders of the CMK can decrypt. TDE, provider-managed keys, and database-native encryption with locally stored keys all leave decryption capability with the database or provider, failing the threat model.

Exam trap

The trap here is treating any encryption at rest as sufficient, when the decisive factor is who controls the keys and when decryption occurs.

84
MCQhard

An organization is migrating a legacy application to the cloud and plans to use a cloud access security broker (CASB). Which of the following is the PRIMARY function of a CASB in securing cloud applications?

A.Performing vulnerability scans on cloud infrastructure
B.Encrypting data at rest in cloud storage
C.Protecting against distributed denial-of-service (DDoS) attacks
D.Enforcing security policies across cloud applications and controlling access
AnswerD

A CASB sits inline between users and cloud services, applying policy enforcement and access control as its core function. This directly addresses the migration scenario's need to govern sanctioned and unsanctioned cloud application usage, covering visibility, data loss prevention, threat protection and compliance enforcement.

Why this answer

The primary function of a CASB is to enforce security policies and control access across cloud applications, acting as an intermediary between users and cloud providers. It provides visibility into cloud usage, applies data loss prevention (DLP) rules, and enforces authentication and authorization policies, which directly addresses the need to secure a legacy application migrated to the cloud.

Exam trap

ISC2 often tests the distinction between a CASB's primary role (policy enforcement and access control) and secondary capabilities (like encryption or DLP), leading candidates to mistake a supporting feature for the core function.

How to eliminate wrong answers

Option A is wrong because vulnerability scanning of cloud infrastructure is typically performed by a cloud security posture management (CSPM) tool or a vulnerability scanner, not a CASB, which focuses on application-level policy enforcement and user access control. Option B is wrong because while a CASB can apply encryption for data in transit or at rest via tokenization or proxy-based encryption, its primary function is not encrypting data at rest; that is a feature of cloud storage services or dedicated encryption tools. Option C is wrong because protecting against DDoS attacks is handled by web application firewalls (WAFs) or DDoS mitigation services, not a CASB, which is designed for visibility, compliance, and access control for cloud applications.

85
Multi-Selectmedium

Which TWO measures are effective for securing container images in a cloud environment?

Select 2 answers
A.Store images in a public registry without scanning
B.Sign images to ensure integrity
C.Use latest tags without version pinning
D.Run containers with root privileges
E.Scan images for vulnerabilities before deployment
AnswersB, E

Signing container images with cryptographic hashes, verified against a trusted registry or key management system, ensures that the image has not been tampered with during transit or storage, directly satisfying the integrity constraint of the cloud environment. This mechanism prevents unauthorised modifications, such as injected malware, from being deployed in production, which is critical for maintaining a secure supply chain.

Why this answer

Option B is correct because cryptographically signing container images (e.g., with Docker Content Trust/Notary or Sigstore Cosign) lets the orchestrator verify image integrity and provenance, ensuring only trusted, untampered images are deployed. Option E is correct because scanning images for known CVEs in OS packages and application dependencies before deployment (using tools like Trivy, Clair, or Grype) catches vulnerabilities early and prevents shipping flawed images into production. Option A is wrong because a public registry without scanning exposes images to tampering and untracked vulnerabilities, undermining supply-chain security.

Option C is wrong because relying on mutable 'latest' tags without version pinning prevents reproducibility and integrity verification, making it easy to deploy unexpected or compromised images. Option D is wrong because running containers as root violates least privilege and dramatically increases the impact of a container escape or compromise.

Exam trap

ISC2 often tests the misconception that 'latest tags are safe because they always point to the most recent version,' but the trap is that 'latest' is a mutable tag that can silently introduce breaking changes or vulnerabilities, whereas version pinning (e.g., using a specific digest or semantic version) ensures deterministic and auditable deployments.

86
MCQmedium

A company is migrating a legacy monolithic application to a cloud-native microservices architecture. The security architect is concerned about securing inter-service communication. Which of the following should be implemented to ensure mutual authentication and encryption between services?

A.Deploy a service mesh with mutual TLS (mTLS) for all inter-service communication.
B.Use shared API keys embedded in each service's configuration.
C.Implement TLS termination at the load balancer with internal certificates.
D.Place all services in the same Virtual Private Cloud (VPC) and restrict ingress with security groups.
AnswerA

A service mesh sidecar proxy intercepts all inter-service traffic and enforces mutual TLS, giving each service a verifiable identity certificate plus encryption in transit. This satisfies the mutual authentication and encryption requirement across the microservices architecture without altering application code.

Why this answer

A service mesh with mutual TLS (mTLS) provides both encryption and mutual authentication for inter-service communication, ensuring that each service verifies the identity of the other before exchanging data. This is the recommended approach for cloud-native microservices because it offloads security concerns from application code and uses X.509 certificates to establish trust, aligning with zero-trust principles.

Exam trap

ISC2 often tests the misconception that network segmentation (VPC/security groups) alone is sufficient for securing inter-service communication, but the CCSP emphasizes that encryption and mutual authentication are required for data-in-transit security in a zero-trust model.

How to eliminate wrong answers

Option B is wrong because shared API keys embedded in configuration do not provide mutual authentication (only one-way authentication) and are vulnerable to leakage, rotation issues, and replay attacks. Option C is wrong because TLS termination at the load balancer means traffic between services is decrypted and re-encrypted, leaving internal traffic potentially unencrypted and without mutual authentication between services themselves. Option D is wrong because placing services in the same VPC with security groups restricts network access but does not provide encryption or mutual authentication for inter-service communication; it relies on network perimeter controls rather than cryptographic identity.

87
MCQmedium

A cloud security team is implementing a Web Application Firewall (WAF) for a public-facing web application. The application uses a REST API with JSON payloads. Which of the following is the WAF's primary benefit?

A.Scanning for data loss prevention (DLP) violations
B.Preventing network-layer DDoS attacks
C.Encrypting data in transit between client and server
D.Inspecting HTTP traffic for malicious payloads
AnswerD

A WAF operates at the application layer, parsing HTTP requests and responses to detect and block malicious payloads such as SQL injection or cross-site scripting before they reach the REST API, directly satisfying the requirement to protect the public-facing JSON-based application.

Why this answer

A WAF operates at Layer 7 (application layer) and is specifically designed to inspect HTTP/HTTPS traffic for malicious payloads such as SQL injection, cross-site scripting (XSS), and JSON-based attacks. For a REST API using JSON, the WAF can parse and validate the JSON structure, blocking malformed or malicious payloads before they reach the application server. This is the primary benefit because it directly protects the application logic from web-based exploits.

Exam trap

ISC2 often tests the distinction between Layer 7 (application) and Layer 3/4 (network) security controls, so candidates mistakenly choose network-layer DDoS protection (Option B) because they confuse WAF with a general-purpose firewall.

How to eliminate wrong answers

Option A is wrong because DLP scanning is a function of data loss prevention tools, not a WAF; a WAF does not inspect data for policy violations like credit card numbers or PII. Option B is wrong because preventing network-layer DDoS attacks (e.g., SYN floods) is the role of a network firewall or DDoS mitigation appliance, not a WAF which focuses on application-layer attacks. Option C is wrong because encrypting data in transit is the job of TLS/SSL (e.g., HTTPS), not a WAF; a WAF inspects decrypted traffic after TLS termination or uses a reverse proxy model, but it does not perform encryption itself.

88
MCQeasy

A company is migrating a legacy web application to the cloud. The application uses a relational database. The security team wants to ensure that database credentials are never hardcoded in the application and are automatically rotated. Which cloud-native approach should be used?

A.Store credentials in environment variables on the application server.
B.Encrypt the database connection string in a configuration file.
C.Use a database user with a long, complex password that is changed manually every 90 days.
D.Use a managed secrets management service that integrates with the database to rotate credentials.
AnswerD

A managed secrets service securely stores credentials and can automatically rotate them on a schedule. The application retrieves credentials at runtime via an API, eliminating hardcoding. This directly satisfies the requirements for secure storage and automatic rotation.

Why this answer

A managed secrets management service provides secure storage and automatic rotation of database credentials. The application retrieves credentials dynamically, so they are never hardcoded. This is the cloud-native best practice for secret management and meets both requirements.

Exam trap

The trap here is thinking that encrypting configuration files or using environment variables is sufficient, when they still expose secrets and lack automatic rotation.

89
MCQmedium

A cloud operations team is building a CI/CD pipeline that deploys container images to a managed Kubernetes cluster. Security policy requires that only images whose vulnerabilities have been scanned and approved can run. The team wants the cluster itself to refuse any pod that references an unapproved image, even if the pipeline is bypassed. Which mechanism should they implement?

A.Enable image vulnerability scanning in the container registry and configure the registry to block pulls of images that exceed the severity threshold.
B.Configure a Kubernetes admission controller with a policy engine, such as Open Policy Agent Gatekeeper, to reject pods referencing images that lack the approved scan attestation.
C.Enable Kubernetes audit logging and forward events to a SIEM so that alerts fire when pods with unapproved images are created.
D.Add a policy check stage to the CI/CD pipeline that fails the build when the scanned image contains vulnerabilities above the threshold.
AnswerB

An admission controller with a policy engine evaluates every pod creation request against policy before the object is persisted, so a pod referencing an image without the required scan attestation is rejected by the cluster regardless of how the manifest was submitted. This enforces the control at the platform layer rather than relying on the pipeline, which is exactly what the scenario requires.

Why this answer

The requirement is preventive enforcement at the cluster level, independent of the deployment channel. A Kubernetes admission controller backed by a policy engine intercepts pod creation and rejects any manifest that does not carry the approved scan attestation. Registry scanning, pipeline gates, and audit alerts each leave a path for an unapproved pod to run, so they cannot satisfy the policy as written.

Exam trap

The trap here is assuming that scanning images in the registry or pipeline is equivalent to blocking unapproved pods from running in the cluster.

90
MCQeasy

A development team is migrating a legacy application to the cloud. Which security testing approach should be adopted early in the CI/CD pipeline to catch vulnerabilities as code is written?

A.Dynamic application security testing (DAST)
B.Penetration testing
C.Runtime application self-protection (RASP)
D.Static application security testing (SAST)
AnswerD

SAST analyses source code without executing it, detecting injection flaws, insecure patterns and hard-coded secrets as developers commit. This satisfies the stem's constraint of catching vulnerabilities early in the CI/CD pipeline, unlike DAST or penetration testing which require a running application.

Why this answer

Static application security testing (SAST) analyzes source code, bytecode, or binary code without executing the application, making it ideal for integration early in the CI/CD pipeline to catch vulnerabilities like SQL injection, buffer overflows, and XSS as code is written. This 'white-box' approach provides immediate feedback to developers, aligning with the shift-left security principle for cloud-native development.

Exam trap

ISC2 often tests the distinction between SAST (white-box, early pipeline) and DAST (black-box, post-deployment), and candidates mistakenly choose DAST because they think 'dynamic' implies early testing, but DAST requires a running application.

How to eliminate wrong answers

Option A is wrong because DAST tests the running application from the outside (black-box), which requires a deployed environment and cannot catch vulnerabilities at the code-writing stage. Option B is wrong because penetration testing is a manual or automated simulated attack on a live system, performed later in the SDLC, not during development. Option C is wrong because RASP is a runtime protection technology embedded in the application runtime environment that monitors and blocks attacks in production, not a testing tool for the CI/CD pipeline.

91
Multi-Selecthard

A cloud security team is designing a secure software development lifecycle (SDLC) for a new microservices application deployed to a public cloud. They want to ensure that security is embedded throughout development and operations. Which two practices should be implemented to achieve this? (Choose two.)

Select 2 answers
A.Conduct threat modeling during the design phase for each microservice.
B.Assign all security responsibilities exclusively to a centralized security team.
C.Automate security gates in the CI/CD pipeline that block builds on critical findings.
D.Disable detailed logging in production to reduce storage costs and improve performance.
E.Perform a full penetration test only after the application is deployed to production.
AnswersA, C

Threat modeling in the design phase identifies potential threats, attack surfaces, and required mitigations before code is written. For microservices, it clarifies trust boundaries between services, data flows, and authentication needs. This early analysis reduces costly rework and aligns security with architecture, making it a core practice for embedding security throughout the SDLC.

Why this answer

Embedding security throughout the SDLC requires proactive design-time analysis and automated enforcement in delivery. Threat modeling during design surfaces risks before code exists, while automated CI/CD security gates ensure every build meets policy and blocks critical findings. Together they shift security left and maintain it through deployment.

Production-only testing, centralized ownership, and reduced logging all weaken or delay security rather than integrating it continuously.

Exam trap

The trap here is equating a single late-stage activity or centralizing security ownership with embedding security throughout the lifecycle.

92
MCQmedium

A cloud application uses an API gateway to expose backend microservices. The security team wants to ensure that clients cannot bypass the gateway and call backend services directly. Which control should be implemented to enforce this?

A.Configure rate limiting on the API gateway to prevent clients from sending excessive requests.
B.Place the backend services in a private subnet and restrict inbound traffic to only the API gateway's security group or identity.
C.Enable mutual TLS on the API gateway so clients must present certificates to connect.
D.Enable access logging on the API gateway and forward logs to a central monitoring service.
AnswerB

By making backend services reachable only from the API gateway's network identity, direct client access is blocked. This enforces the gateway as the single entry point and ensures all requests pass through the gateway's authentication, throttling, and logging controls.

Why this answer

Enforcing that backend services accept traffic only from the API gateway requires network-level restriction, such as private subnets combined with security group or identity-based rules. Authentication, rate limiting, and logging at the gateway improve security but do not prevent a client from reaching a backend endpoint that remains exposed.

Exam trap

The trap here is assuming that strong gateway controls like mutual TLS or rate limiting also prevent direct backend access, when only network isolation of the backends enforces the gateway path.

93
MCQmedium

An IAM policy named S3ReadOnlyAccess has DefaultVersionId v3. What does this indicate?

A.The policy is newly created.
B.The policy is currently using version v3 as the default.
C.The policy has three custom versions.
D.The policy cannot be attached to any entity.
AnswerB

DefaultVersionId identifies which of the policy's stored versions is currently applied to attached principals. v3 being the default means that document governs permissions; earlier versions remain retrievable but inactive, so the effective policy is version three.

Why this answer

The DefaultVersionId of an IAM policy indicates which version is currently active and enforced when the policy is attached to an IAM user, group, or role. Since the policy is named S3ReadOnlyAccess and has DefaultVersionId v3, version v3 is the default and is being used for access control decisions. This is the standard behavior for IAM policies in AWS, where you can have multiple versions but only one is designated as the default.

Exam trap

ISC2 often tests the misconception that DefaultVersionId indicates the total number of versions or that a policy with a non-v1 default is somehow broken or unattachable, when in fact it simply shows which version is active.

How to eliminate wrong answers

Option A is wrong because a newly created policy would have DefaultVersionId v1, not v3, as the first version is always v1. Option C is wrong because DefaultVersionId v3 does not imply there are exactly three custom versions; there could be more versions (e.g., v1, v2, v3, v4) and only v3 is set as default, or some versions may be non-default. Option D is wrong because a policy with a default version can be attached to any entity; the DefaultVersionId simply indicates which version is active, and the policy remains attachable unless explicitly restricted.

94
MCQhard

A company uses a serverless architecture with AWS Lambda to process user-uploaded files. The Lambda function is triggered by an S3 bucket event. While reviewing security, the architect wants to ensure that the Lambda function cannot be invoked by unauthorized S3 buckets or accounts. What is the most secure configuration?

A.Use a condition in the policy that checks the source IP address.
B.Place the Lambda function inside a VPC with a VPC endpoint for S3.
C.Configure the Lambda function's resource-based policy to grant permission only to the specific S3 bucket ARN and its owner account.
D.Attach a resource-based policy that allows any S3 bucket to invoke the function.
AnswerC

A resource-based policy naming the exact S3 bucket ARN and owner account restricts invocation to that single source, satisfying the requirement that unauthorised buckets or accounts cannot trigger the function. Broader service principals would permit other buckets.

Why this answer

The most secure way to restrict Lambda invocation to a specific S3 bucket is to use a resource-based policy that explicitly grants the `lambda:InvokeFunction` permission only to the trusted bucket's ARN and the owning AWS account. This ensures that even if another S3 bucket or account attempts to trigger the function, the invocation is denied by the Lambda permission model, which evaluates both the resource-based policy and the caller's identity.

Exam trap

The trap here is that candidates often confuse network-level controls (like VPC placement or IP filtering) with identity-based access controls, failing to realize that S3 event notifications invoke Lambda through AWS's internal service-to-service channel, which bypasses network restrictions and requires explicit resource-based policy conditions.

How to eliminate wrong answers

Option A is wrong because checking the source IP address is ineffective for S3 event notifications, as S3 invokes Lambda via AWS internal services, not from a fixed public IP; the source IP can vary and is not a reliable control for cross-account or cross-bucket invocation. Option B is wrong because placing the Lambda function inside a VPC with a VPC endpoint for S3 controls network traffic but does not restrict which S3 buckets or accounts can invoke the function; invocation permissions are governed by IAM and resource-based policies, not network placement. Option D is wrong because allowing any S3 bucket to invoke the function violates the principle of least privilege and would permit unauthorized buckets or accounts to trigger the Lambda, leading to potential data exfiltration or abuse.

95
Multi-Selecthard

Which THREE are key considerations when designing a secure software development lifecycle (SSDLC) for cloud applications?

Select 3 answers
A.Static code analysis during development
B.Threat modeling at design phase
C.Security testing in production
D.Using a single cloud provider
E.Secure coding standards
AnswersA, B, E

Static code analysis scans source during development, catching injection flaws and insecure patterns before deployment. It satisfies the SSDLC requirement to embed security checks early in the build phase rather than relying on production controls.

Why this answer

Static code analysis during development (A) is correct because SAST tools scan source code for vulnerabilities such as injection flaws and insecure API usage before deployment, shifting security left in the SSDLC. Threat modeling at the design phase (B) is correct because it identifies trust boundaries, data flows, and potential attack vectors (e.g., STRIDE) early, when architectural changes are cheapest to make. Secure coding standards (E) are correct because they give developers concrete, enforceable rules (e.g., OWASP ASVS, input validation, output encoding) that reduce the introduction of common vulnerabilities in cloud-native code.

Security testing in production (C) is not a core SSDLC design consideration; while runtime monitoring and DAST may occur post-deployment, production testing is an operational activity rather than a lifecycle design principle. Using a single cloud provider (D) is irrelevant to SSDLC security design and may even increase lock-in and single-point-of-failure risk, so it is not a key consideration.

Exam trap

ISC2 often tests the distinction between activities that are part of the secure development lifecycle (design, code, test) versus operational security tasks (production testing), and candidates mistakenly select 'Security testing in production' because they confuse it with runtime security monitoring or penetration testing.

96
MCQmedium

A healthcare company runs a containerized patient portal on a managed Kubernetes service. The security team needs to ensure that container images cannot be deployed if they contain known critical vulnerabilities. The build pipeline already produces an SBOM. Which control should be enforced at the admission layer to meet this requirement?

A.Configure network policies to limit pod-to-pod traffic and enable mutual TLS between all services in the cluster.
B.Enable a runtime security agent that alerts when a container executes a known malicious binary, and route alerts to the SOC for manual triage.
C.Configure the cluster's admission controller to reject pods whose images are not signed by the organization's trusted cosign key, and run a vulnerability scan as part of the CI pipeline before signing.
D.Restrict the cluster's image registry to an internal private registry and require developers to push images only to that registry.
AnswerC

Admission control that enforces signature verification ensures only images approved by the CI pipeline (which includes vulnerability scanning) are admitted. Because the SBOM is already produced, integrating scanning into the pipeline and signing only clean images gives a verifiable, cryptographically enforced gate at deploy time, satisfying the requirement without relying on runtime detection.

Why this answer

Preventing deployment of vulnerable images requires a preventive control at admission that verifies images were scanned and approved. Signing images after a CI vulnerability scan and enforcing signature verification in the admission controller creates a cryptographic gate. Detection, private registries, and network controls do not evaluate image contents before scheduling, so they cannot block vulnerable workloads.

Exam trap

The trap here is assuming that scanning images in CI alone is sufficient, when the scan result must be enforced at admission through signature or policy verification to actually prevent deployment.

97
Multi-Selectmedium

Which THREE of the following are common challenges in securing serverless applications?

Select 3 answers
A.Lack of control over the underlying kernel and OS
B.Insecure handling of event source inputs
C.Vulnerabilities in third-party libraries and dependencies
D.Increased attack surface due to many small functions
E.Difficulty in applying stateful firewall rules
AnswersB, C, D

Event source inputs reach functions as untrusted payloads from queues, buckets, HTTP triggers or databases. Without validation and sanitisation, injection and malformed-data attacks succeed, making insecure handling of event source inputs a genuine serverless security challenge.

Why this answer

Option B is correct because serverless functions are triggered by diverse event sources (API Gateway, S3, SNS, SQS, etc.), and failing to validate or sanitize these inputs exposes functions to injection and event-injection attacks. Option C is correct because serverless deployments rely heavily on third-party packages and runtime dependencies, so vulnerable or outdated libraries become a primary risk since providers do not patch application code. Option D is correct because decomposing an application into many small functions multiplies entry points and triggers, enlarging the attack surface that must be individually secured and monitored.

Option A is not a distinguishing serverless challenge since the provider manages the kernel and OS, removing that control burden from the customer. Option E is not applicable because serverless architectures are inherently stateless and typically rely on security groups, IAM, and WAF rather than stateful firewall rules.

Exam trap

ISC2 often tests the misconception that serverless eliminates all infrastructure security concerns, leading candidates to overlook the critical need for input validation and dependency management, while incorrectly assuming that network controls like firewalls are still applicable.

98
Multi-Selectmedium

Which THREE of the following are essential components of a Secure Software Development Lifecycle (SSDLC) in the cloud? (Choose three.)

Select 3 answers
A.Static application security testing (SAST) in CI/CD
B.Dynamic application security testing (DAST) in staging
C.Manual code reviews without automation
D.Threat modeling during design phase
E.Annual penetration testing only
AnswersA, B, D

SAST finds vulnerabilities in source code early.

Why this answer

SAST tools scan source code, bytecode, or binaries for vulnerabilities like SQL injection or buffer overflows early in the development cycle. Integrating SAST into the CI/CD pipeline enables automated, continuous security checks on every commit or build, which is a core practice of a Secure Software Development Lifecycle (SSDLC) in the cloud. This shift-left approach catches flaws before they reach production, reducing remediation cost and risk.

Exam trap

ISC2 often tests the misconception that manual reviews are a primary or essential component of an SSDLC in the cloud, when in fact automation is critical for speed and consistency, and they also test the trap that annual penetration testing is sufficient for cloud environments, which require continuous security validation.

99
MCQmedium

A large enterprise is migrating a legacy .NET application to Azure App Service. The application currently stores session state in-memory on the web server. During the migration, the team plans to horizontally scale the application across multiple instances. The security team requires that session data remain confidential and be available even if an instance fails. Which solution should the team implement?

A.Store session data in Azure SQL Database with column-level encryption
B.Use Azure Redis Cache to store session state with encryption enabled
C.Encrypt session data and store it as a client-side cookie
D.Configure Application Gateway with cookie-based affinity (sticky sessions)
AnswerB

Azure Redis Cache externalises session state from instance memory, so any scaled instance can read the same data and a failed instance loses nothing. Encryption at rest and in transit keeps the session data confidential, meeting both availability and confidentiality constraints.

Why this answer

Azure Redis Cache with encryption enabled provides a secure, centralized session store that persists data independently of individual web server instances. This ensures session data remains available even if an instance fails, and encryption protects confidentiality in transit and at rest, meeting the security team's requirements for horizontal scaling.

Exam trap

ISC2 often tests the distinction between availability and affinity, where candidates mistakenly choose sticky sessions (Option D) thinking they solve availability, but sticky sessions actually create a single point of failure by binding a user to one instance.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database with column-level encryption does not provide the low-latency, in-memory performance needed for session state in a horizontally scaled web application, and it introduces unnecessary database overhead and cost. Option C is wrong because storing encrypted session data as a client-side cookie violates the requirement for availability after instance failure, as the data is tied to the client and not centrally managed, and cookies have size limits (typically 4 KB) that cannot accommodate large session states. Option D is wrong because Application Gateway with cookie-based affinity (sticky sessions) pins a client to a specific instance, which prevents true horizontal scaling and does not ensure session data availability if that instance fails, as the session remains in-memory on that single server.

100
MCQeasy

A cloud team is building a web application that stores user session tokens in the browser. A security review recommends that the tokens be inaccessible to JavaScript to reduce the impact of cross-site scripting attacks. Which cookie attribute should be set on the session token?

A.Secure
B.SameSite=Strict
C.HttpOnly
D.Domain
AnswerC

HttpOnly prevents client-side scripts from accessing the cookie through the Document Object Model, so a cross-site scripting flaw cannot directly read the session token. This directly mitigates the risk described in the security review while the cookie remains usable for server-side session management.

Why this answer

HttpOnly instructs the browser to hide the cookie from client-side scripts, so a cross-site scripting vulnerability cannot directly exfiltrate the session token. Secure, SameSite, and Domain attributes address transport, cross-site request behaviour, and scope respectively, but none prevents script access.

Exam trap

The trap here is conflating Secure with HttpOnly, assuming that HTTPS-only transmission also stops JavaScript from reading the cookie, when only HttpOnly controls script access.

101
MCQeasy

A cloud operations team is deploying a web application that stores configuration files and application logs in an object storage bucket. The security policy requires that data be encrypted at rest, and the team wants the cloud provider to manage the encryption keys with minimal operational overhead. The bucket must remain accessible to the application without code changes. Which approach should the team use?

A.Use server-side encryption with customer-provided keys, supplying the key in each request so the provider does not store it.
B.Rely on transport layer security for data in transit and document that encryption at rest is not required for configuration files.
C.Implement client-side encryption in the application so that objects are encrypted before upload, using keys stored in the application configuration.
D.Enable server-side encryption with provider-managed keys on the bucket, which automatically encrypts objects at rest.
AnswerD

Server-side encryption with provider-managed keys encrypts objects at rest and the cloud provider handles key storage, rotation, and access transparently. The application continues to read and write objects without modification, meeting the minimal-overhead and no-code-change requirements. This directly satisfies the policy that data be encrypted at rest while keeping operations simple.

Why this answer

Provider-managed server-side encryption is the lowest-overhead way to meet an encryption-at-rest requirement because the cloud service handles key storage, rotation, and cryptographic operations automatically. The application's read and write operations remain unchanged, so no code modifications are needed. This satisfies both the security policy and the operational constraints described by the team.

Exam trap

The trap here is assuming that encryption at rest always requires customer-managed keys or client-side code, when provider-managed server-side encryption already satisfies the policy with less overhead.

102
MCQmedium

During a code review, a developer identifies that an application uses input from an HTTP request to generate a SQL query string. What is the primary security concern?

A.Buffer overflow
B.Insecure deserialization
C.Cross-site scripting (XSS)
D.SQL injection
AnswerD

Concatenating HTTP request input into a SQL query string lets attacker-supplied syntax alter the query's structure, so the database executes unintended statements. This is SQL injection, the direct consequence of mixing untrusted input with query code without parameterisation.

Why this answer

Directly concatenating user-supplied input from an HTTP request into a SQL query string allows an attacker to inject arbitrary SQL commands. This can lead to unauthorized data access, data manipulation, or even complete database compromise. The primary security concern is SQL injection, which violates the confidentiality and integrity of cloud-hosted databases.

Exam trap

ISC2 often tests the distinction between input validation issues (like SQL injection) and output encoding issues (like XSS), so the trap here is confusing a server-side injection attack with a client-side script injection attack.

How to eliminate wrong answers

Option A is wrong because buffer overflow exploits typically target memory corruption in low-level languages like C/C++, not SQL query string generation in application code. Option B is wrong because insecure deserialization involves untrusted data being deserialized into objects, not the direct injection of SQL syntax into a query string. Option C is wrong because cross-site scripting (XSS) involves injecting client-side scripts into web pages viewed by other users, whereas this scenario directly manipulates a server-side SQL query.

103
Multi-Selecthard

A security team is reviewing the software development lifecycle for a cloud-native application. They want to shift security left and reduce the cost of remediating defects. Which two practices best support this goal? (Choose two.)

Select 2 answers
A.Add infrastructure as code scanning that detects misconfigurations in templates before they are deployed to any environment.
B.Conduct annual security awareness training for all engineers and track completion in the learning management system.
C.Require developers to submit a written security exception form for every new cloud resource they provision.
D.Integrate static application security testing into the build pipeline so that code is analyzed automatically on every commit.
E.Perform a full penetration test of the application only after it has been deployed to the production environment.
AnswersA, D

Scanning infrastructure as code templates before deployment catches insecure settings such as public buckets or permissive security groups at authoring time. Because the fix is a template change reviewed like any other code, remediation is cheap and consistent across environments. This is a concrete shift-left control that prevents misconfigurations from ever reaching the cloud account.

Why this answer

Shifting security left means embedding automated checks into the earliest stages of development so defects are found and fixed while changes are small. Static analysis on every commit and infrastructure as code scanning before deployment both deliver immediate, low-cost feedback in the developer workflow. Late penetration tests, manual exception forms, and annual training do not detect defects at authoring time and therefore do not lower remediation cost.

Exam trap

The trap here is equating any security activity added to the lifecycle with shifting left, when the defining characteristic is early automated detection in the developer workflow.

104
MCQmedium

A cloud security engineer is reviewing a serverless application built with AWS Lambda. The function processes messages from an Amazon SQS queue and writes to an Amazon DynamoDB table. The engineer needs to ensure that the Lambda function has only the necessary permissions to perform its tasks. Which approach best follows the principle of least privilege?

A.Store AWS credentials in environment variables and use them in the Lambda function code.
B.Attach a managed policy like AmazonSQSFullAccess and AmazonDynamoDBFullAccess to the Lambda execution role.
C.Create a custom IAM policy that allows sqs:ReceiveMessage on the specific queue and dynamodb:PutItem on the specific table, and attach it to the Lambda execution role.
D.Use AWS IAM roles for service accounts (IRSA) to assign permissions to the Lambda function.
AnswerC

A custom IAM policy scoped to the exact actions and resources required adheres to least privilege. The Lambda function needs to receive messages from the designated SQS queue and put items into the designated DynamoDB table. This granular policy minimizes permissions and reduces risk, ensuring the function cannot perform other actions or access other resources.

Why this answer

The principle of least privilege requires granting only the permissions necessary for the function's operation. A custom IAM policy that allows sqs:ReceiveMessage on the specific queue and dynamodb:PutItem on the specific table ensures the Lambda function can perform its tasks without excess permissions. This minimizes the potential impact of a compromised function and aligns with AWS security best practices.

Exam trap

The trap here is assuming that managed policies or storing credentials in environment variables are acceptable for least privilege, when they grant excessive permissions or introduce security risks.

105
MCQhard

A financial services company uses a multi-region cloud deployment for its trading application. The application consists of a web frontend, a REST API, and a relational database. Recently, a penetration test revealed that an attacker could perform a time-based blind SQL injection through the API's search functionality. The injection allows the attacker to enumerate database contents by observing response times. The development team was already aware of the issue but had prioritized other features. The security team now demands immediate remediation. The application is critical and cannot be taken offline. Which of the following is the most effective immediate action to mitigate the risk without modifying the application code?

A.Deploy a Web Application Firewall (WAF) with a rule to block SQL injection patterns
B.Implement rate limiting on the API endpoint
C.Enable DDoS protection on the cloud load balancer
D.Enable transparent data encryption (TDE) on the database
AnswerA

A WAF inspects HTTP requests at the edge and blocks SQL injection signatures before they reach the API, satisfying the no-code-change constraint. Because the flaw is exploitable through the search parameter, virtual patching neutralises the time-based blind injection immediately while the application stays online.

Why this answer

A WAF can inspect incoming HTTP requests and block those matching SQL injection patterns (e.g., SQL keywords, special characters) without modifying application code. Since the vulnerability is a time-based blind SQL injection, a WAF with a dedicated SQL injection rule set can immediately stop the attack vector by filtering malicious payloads at the edge, providing a virtual patch while the code fix is developed. This is the only option that directly addresses the injection vector without requiring code changes or downtime.

Exam trap

ISC2 often tests the misconception that rate limiting or DDoS protection can mitigate application-layer attacks like SQL injection, but these controls address availability threats, not data exfiltration or injection vulnerabilities.

How to eliminate wrong answers

Option B is wrong because rate limiting only restricts the number of requests per time window, which does not prevent a single crafted SQL injection payload from executing; it merely slows down enumeration but does not block the injection itself. Option C is wrong because DDoS protection mitigates volumetric attacks aimed at overwhelming resources, not application-layer attacks like SQL injection; it does not inspect payload content. Option D is wrong because transparent data encryption (TDE) protects data at rest in the database, but the SQL injection attack exploits the API to extract data in transit or via response timing, so encryption does not prevent the injection or the data exfiltration.

106
MCQeasy

A cloud security engineer reviews this Terraform configuration for a security group. Which change is necessary to improve security?

A.Use a broader CIDR for ingress.
B.Restrict egress to specific ports.
C.Change protocol to UDP.
D.Remove the ingress rule.
AnswerB

Default security groups permit all outbound traffic, so an attacker with a foothold can exfiltrate data or reach command-and-control hosts on any port. Narrowing egress to only the ports the workload genuinely requires enforces least privilege outbound, directly satisfying the stem's demand to improve the configuration's security posture.

Why this answer

The default egress rule in Terraform's AWS security group allows all outbound traffic (0.0.0.0/0, all ports, all protocols). This violates the principle of least privilege. Restricting egress to only specific ports and protocols (e.g., TCP/443 for HTTPS) reduces the attack surface and prevents data exfiltration or unintended outbound connections.

Exam trap

Candidates often focus solely on ingress rules in security groups, neglecting the security risk of overly permissive egress rules, which can lead to data exfiltration.

How to eliminate wrong answers

Option A is wrong because using a broader CIDR (e.g., 0.0.0.0/0) for ingress would increase the attack surface, allowing traffic from any IP address, which is less secure. Option C is wrong because changing the protocol to UDP does not inherently improve security; UDP is connectionless and can be used for attacks like amplification, and the protocol choice should be based on application requirements, not security generalization. Option D is wrong because removing the ingress rule entirely would block all inbound traffic, which may break legitimate application functionality; the issue is with overly permissive egress, not ingress.

107
MCQmedium

A security architect is designing a CI/CD pipeline for a cloud-native application. The team wants to automatically scan container images for vulnerabilities before deployment. Which of the following is the most effective approach?

A.Manually review images before each deployment
B.Integrate a container image scanner into the pipeline
C.Perform vulnerability scanning at runtime using a host-based agent
D.Scan the network for open ports on the container hosts
AnswerB

Embedding a container image scanner as a pipeline stage inspects each built image for known CVEs before deployment, failing the build on policy violations. This shifts detection left, blocking vulnerable images from reaching the cluster rather than scanning after release.

Why this answer

Integrating a container image scanner into the CI/CD pipeline ensures that vulnerabilities are detected early, before the image is deployed to production. This approach automates security checks as part of the build process, aligning with DevSecOps principles by shifting security left. Tools like Trivy, Clair, or Anchore can be configured to fail the pipeline if critical vulnerabilities are found, preventing insecure images from reaching runtime.

Exam trap

The trap here is that candidates confuse runtime host-based scanning (Option C) with image scanning, but the question specifically asks for scanning before deployment, making pipeline integration the only correct choice that enforces security gates early in the lifecycle.

How to eliminate wrong answers

Option A is wrong because manual review is not scalable, error-prone, and cannot keep pace with the frequency of deployments in a CI/CD pipeline, violating the automation principle of secure DevOps. Option C is wrong because runtime scanning with a host-based agent detects vulnerabilities only after the container is already running, missing the opportunity to block deployment of vulnerable images and potentially exposing the environment to exploitation. Option D is wrong because scanning the network for open ports on container hosts addresses network-level exposure, not the vulnerabilities within the container image itself, and is a reactive measure unrelated to image security.

108
MCQhard

A security architect is designing a cloud-native application using microservices. They decide to implement mutual TLS (mTLS) for service-to-service communication in a Kubernetes cluster with hundreds of services. What is the primary challenge in managing mTLS certificates in this dynamic environment?

A.High latency due to encryption overhead
B.Certificate revocation and rotation
C.Incompatibility with HTTP/2
D.Increased complexity in load balancer configuration
AnswerB

Hundreds of short-lived pods mean certificates expire and rotate constantly, so revocation and rotation at scale becomes the operational bottleneck. Manual or static PKI cannot track ephemeral workload identities, making automated issuance and revocation the primary management challenge in this dynamic Kubernetes environment.

Why this answer

In a dynamic Kubernetes environment with hundreds of microservices, mTLS certificates must be frequently rotated and revoked to maintain security, especially as services scale up/down and pods are replaced. Manual certificate management is impractical, so automated solutions like SPIFFE/SPIRE or Istio’s Citadel are required to handle the lifecycle at scale. The primary challenge is not the encryption overhead but the operational complexity of ensuring every service has a valid, non-expired certificate and that compromised certificates can be promptly revoked across the mesh.

Exam trap

The trap here is that candidates confuse the operational challenge of certificate lifecycle management with perceived performance issues (latency) or compatibility concerns, when in fact mTLS is designed to work efficiently with modern protocols and the real difficulty is maintaining trust in a rapidly changing service mesh.

How to eliminate wrong answers

Option A is wrong because mTLS encryption overhead is minimal with modern hardware and optimized libraries (e.g., AES-NI, TLS 1.3), and latency is not the primary challenge in a dynamic environment. Option C is wrong because mTLS is fully compatible with HTTP/2; in fact, gRPC (which uses HTTP/2) commonly relies on mTLS for secure service-to-service communication. Option D is wrong because mTLS does not inherently increase load balancer configuration complexity; load balancers can terminate or pass-through mTLS, and the challenge lies in certificate lifecycle management, not load balancer setup.

109
MCQmedium

A cloud team is integrating a third-party analytics service into its application. The vendor requires access to data in the organization's object storage bucket. Security policy forbids sharing long-lived cloud credentials with third parties. Which approach best satisfies the policy while granting the vendor the required access?

A.Create an IAM user for the vendor and issue an access key, then rotate the key every 90 days through a documented process.
B.Generate a pre-signed URL for the bucket with a long expiration and send it to the vendor so they can retrieve the objects.
C.Configure a cross-account IAM role in the organization's account that trusts the vendor's account, and have the vendor assume it to obtain temporary credentials scoped to the bucket.
D.Enable public read access on the bucket and rely on the vendor's network allowlist to restrict who can retrieve the objects.
AnswerC

Cross-account role assumption lets the vendor's principals obtain short-lived credentials through STS, with permissions limited to the bucket and actions required. No long-lived secret is shared, the trust relationship can be revoked centrally, and every assumption is logged. This aligns with the policy and with least privilege for third-party access.

Why this answer

The policy requires that third parties never hold long-lived cloud credentials. Cross-account role assumption issues temporary, scoped credentials through the cloud provider's token service, so the vendor authenticates to its own identity and receives access only to the designated bucket. Access keys, long-lived pre-signed URLs, and public buckets all create durable or unauthenticated access paths that the policy prohibits.

Exam trap

The trap here is treating credential rotation or a long-lived pre-signed URL as equivalent to eliminating shared long-lived credentials.

110
MCQeasy

Which of the following is the best way to protect a web application from cross-site scripting (XSS) attacks?

A.Encode all output that is rendered in HTML.
B.Implement a Content Security Policy (CSP) as the sole defense.
C.Use a combination of input validation, output encoding, and Content Security Policy.
D.Validate all user input on the server side.
AnswerC

XSS arises from untrusted data reaching the browser as markup, so layered defences are needed: validation rejects malformed input, output encoding neutralises injected script, and Content Security Policy restricts what executes. No single control covers stored, reflected and DOM-based variants, satisfying the best-practice requirement.

Why this answer

Cross-site scripting (XSS) attacks exploit multiple vectors, and no single defense is sufficient. Input validation prevents malicious payloads from being stored or processed, output encoding ensures that any residual dangerous characters are rendered inert in the HTML context, and Content Security Policy (CSP) provides a robust, browser-enforced layer that can block inline scripts and restrict script sources even if other defenses fail. This defense-in-depth approach aligns with the OWASP XSS prevention cheat sheet and is the recommended strategy for cloud-hosted web applications.

Exam trap

ISC2 often tests the misconception that a single security control (like output encoding or CSP alone) is sufficient, when the correct answer always requires a defense-in-depth combination of input validation, output encoding, and CSP.

How to eliminate wrong answers

Option A is wrong because output encoding alone does not prevent XSS in all contexts (e.g., JavaScript event handlers, CSS, or URL contexts require context-specific encoding) and does not address stored XSS where the payload is executed before encoding is applied. Option B is wrong because implementing CSP as the sole defense is insufficient; CSP can be bypassed if the application has JSONP endpoints, unsafe-inline fallbacks, or misconfigured directives, and it does not remediate existing XSS vulnerabilities in the application code. Option D is wrong because server-side input validation alone cannot stop XSS; it can be bypassed with encoding variations (e.g., double URL encoding, Unicode escapes) and does not protect against reflected or DOM-based XSS where the payload is generated client-side without server validation.

111
MCQhard

A cloud security engineer needs to ensure that a containerized application running in a Kubernetes cluster securely stores and rotates database credentials. Which is the most appropriate solution?

A.Store credentials as environment variables in the pod manifest
B.Embed credentials in the container image during build
C.Use a secrets management system integrated with Kubernetes, such as HashiCorp Vault with CSI driver
D.Use Kubernetes Secrets without encryption at rest
AnswerC

Vault's CSI driver mounts secrets directly into pods as ephemeral volumes, so credentials never persist in etcd or manifest files, and Vault's lease mechanism rotates them automatically. This satisfies the requirement for secure storage and rotation of database credentials within Kubernetes.

Why this answer

HashiCorp Vault integrated with the Kubernetes CSI (Container Storage Interface) driver allows dynamic, short-lived database credentials to be injected into pods as volumes, enabling automatic rotation without application changes. This approach ensures secrets are never stored in the cluster's etcd or exposed in environment variables, aligning with the principle of least privilege and compliance requirements for credential rotation.

Exam trap

ISC2 often tests the misconception that Kubernetes Secrets are inherently secure because they are base64-encoded, but the trap is that base64 is not encryption, and without encryption at rest or an external secrets manager, they are vulnerable to etcd compromise.

How to eliminate wrong answers

Option A is wrong because storing credentials as environment variables in the pod manifest exposes them in plaintext in the cluster's etcd and in any logs or dumps that capture environment variables, violating security best practices for secret management. Option B is wrong because embedding credentials in the container image during build makes them immutable and accessible to anyone with image pull access, preventing rotation without rebuilding and redeploying the image. Option D is wrong because Kubernetes Secrets without encryption at rest store secrets in base64-encoded plaintext in etcd, which is not secure against unauthorized access to the underlying storage, and they lack native rotation capabilities.

112
MCQmedium

A company develops a microservices application and wants to ensure secrets such as API keys and database credentials are not exposed in container images. Which approach best meets this requirement?

A.Hardcode secrets in the application code and obfuscate with encryption.
B.Use a secrets management service such as HashiCorp Vault to inject secrets at runtime.
C.Pass secrets as environment variables during container deployment.
D.Store secrets in a separate configuration file within the image.
AnswerB

HashiCorp Vault stores credentials outside the image and injects them into the container at runtime, so no secret is baked into layers or environment variables. This satisfies the requirement that API keys and database credentials never appear in container images, where they would be extractable.

Why this answer

A secrets management service like HashiCorp Vault allows secrets to be dynamically injected into containers at runtime, ensuring they never reside in the image. This approach decouples secrets from the application artifact, adhering to the principle of least privilege and immutable infrastructure. Vault can inject secrets via sidecar containers, init containers, or API calls, preventing exposure in image layers or configuration files.

Exam trap

ISC2 often tests the misconception that environment variables are a secure way to pass secrets because they are not in the image, but the trap is that environment variables are still exposed in the container's runtime environment and orchestration metadata, making them vulnerable to leakage via logs, debugging tools, or misconfigured RBAC.

How to eliminate wrong answers

Option A is wrong because hardcoding secrets in application code, even with obfuscation, is insecure—encryption keys must still be stored somewhere, and obfuscation can be reversed, violating the core security principle of not embedding secrets in code. Option C is wrong because passing secrets as environment variables during deployment, while better than hardcoding, still exposes them in the container's process list, logs, and orchestration metadata, and they can be read from the host or via /proc. Option D is wrong because storing secrets in a separate configuration file within the image means the secrets are baked into the image layers, making them accessible to anyone who can pull the image, and they persist in registries and caches.

113
MCQmedium

A DevSecOps team is integrating static application security testing (SAST) into their CI/CD pipeline. Which of the following is the PRIMARY benefit of performing SAST during the build phase rather than later in the pipeline?

A.It identifies runtime vulnerabilities such as SQL injection
B.It reduces false positives compared to dynamic analysis
C.It enables early detection of vulnerabilities before deployment
D.It scans running applications to find configuration issues
AnswerC

SAST analyses source code during the build, so flaws are flagged in the commit that introduced them, before artefacts reach staging or production. This shifts remediation left, cutting the cost and risk of fixing defects after deployment, which is the stem's stated build-phase constraint.

Why this answer

Performing SAST during the build phase allows the team to identify security vulnerabilities in the source code before the application is compiled, packaged, or deployed. This early detection reduces the cost and effort of remediation because issues are found at the point of code creation, not after deployment. The primary benefit is shifting security left to catch defects before they reach production.

Exam trap

ISC2 often tests the concept of 'shift left' security, and the trap here is confusing SAST's static analysis capability with runtime detection, leading candidates to incorrectly choose options that describe dynamic or runtime testing benefits.

How to eliminate wrong answers

Option A is wrong because SAST analyzes source code statically and cannot identify runtime vulnerabilities like SQL injection that depend on dynamic input and database interaction; those are better detected by DAST or IAST. Option B is wrong because SAST often produces more false positives than dynamic analysis due to its lack of runtime context, not fewer. Option D is wrong because SAST does not scan running applications; it scans source code or binaries without execution, whereas configuration issues in running apps are found by tools like configuration scanning or DAST.

114
Multi-Selectmedium

A cloud security engineer is reviewing the software development lifecycle for a team building a containerized application on a public cloud. The team wants to shift security left and reduce vulnerabilities in production images. Which two practices should be implemented to achieve this? (Choose two.)

Select 2 answers
A.Integrate static application security testing (SAST) into the CI pipeline
B.Store container images in a private registry with access controls
C.Scan container images for known vulnerabilities in the CI/CD pipeline
D.Perform a penetration test of the production environment annually
E.Enable runtime threat detection in the production Kubernetes cluster
AnswersA, C

SAST analyzes source code or binaries for security flaws early in the development process, before deployment. Integrating it into the CI pipeline ensures every commit is scanned, allowing developers to fix issues quickly. This directly supports shifting security left by catching vulnerabilities such as injection flaws or insecure cryptographic usage before they reach production images.

Why this answer

Shifting security left means embedding security checks early in the development lifecycle. SAST finds code-level flaws at commit time, and container image scanning finds vulnerable packages at build time. Both prevent vulnerable artifacts from reaching production.

Runtime detection, annual penetration tests, and private registries are valuable but operate after deployment or only control access, not vulnerability reduction.

Exam trap

The trap here is confusing post-deployment controls like runtime detection or penetration testing with shift-left practices that prevent vulnerabilities earlier.

← PreviousPage 2 of 2 · 114 questions total

Ready to test yourself?

Try a timed practice session using only Cloud App Security questions.