Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

Which API Gateway security feature limits the number of requests from a client to prevent abuse or DoS attacks?

⚠ Common exam trap

The trap is that all four options are legitimate API security features, so candidates must match the specific control to the specific threat — volume abuse maps to rate limiting, not authentication or content inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rate limiting

Rate limiting (also called throttling) caps the number of requests a client can make within a defined time window, protecting backend services from abuse, brute-force attempts, and denial-of-service floods. API gateways implement this with token bucket or leaky bucket algorithms, returning HTTP 429 Too Many Requests when the limit is exceeded. It is the primary control for request-volume abuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Rate limiting

    Why this is correct

    Rate limiting caps how many requests a client may issue per time window, throttling abusive bursts before they exhaust backend capacity. This directly satisfies the stem's constraint of preventing abuse or denial-of-service attacks, unlike authentication or encryption features that address identity and confidentiality instead.

  • ✗

    JWT validation

    Why it's wrong here

    JWT validation verifies token signature, issuer and expiry to authenticate callers; it does not count or cap request volume. Throttling or rate limiting performs that function. JWT validation is tempting because it is an API Gateway security feature, but it addresses identity assurance, not abuse prevention.

  • ✗

    WAF integration

    Why it's wrong here

    A WAF inspects HTTP request content against rule sets to block injection, XSS and similar payload attacks; it does not count requests per client over time. Rate limiting or throttling is the feature that caps request volume to prevent abuse or DoS, so WAF integration would be correct if the requirement were filtering malicious request patterns.

  • ✗

    Mutual TLS

    Why it's wrong here

    Mutual TLS authenticates both client and server via certificates and encrypts the channel in transit; it does not meter request frequency. Throttling or rate limiting enforces a requests-per-interval quota per client to stop abuse or DoS. Mutual TLS would be correct if the requirement were verifying client identity or securing transport.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.