CCSP Cloud Platform and Infrastructure Security Practice Question
Which API Gateway security feature limits the number of requests from a client to prevent abuse or DoS attacks?
⚠ Common exam trap
The trap is that all four options are legitimate API security features, so candidates must match the specific control to the specific threat — volume abuse maps to rate limiting, not authentication or content inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rate limiting
Rate limiting (also called throttling) caps the number of requests a client can make within a defined time window, protecting backend services from abuse, brute-force attempts, and denial-of-service floods. API gateways implement this with token bucket or leaky bucket algorithms, returning HTTP 429 Too Many Requests when the limit is exceeded. It is the primary control for request-volume abuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Rate limiting
Why this is correct
Rate limiting caps how many requests a client may issue per time window, throttling abusive bursts before they exhaust backend capacity. This directly satisfies the stem's constraint of preventing abuse or denial-of-service attacks, unlike authentication or encryption features that address identity and confidentiality instead.
- ✗
JWT validation
Why it's wrong here
JWT validation verifies token signature, issuer and expiry to authenticate callers; it does not count or cap request volume. Throttling or rate limiting performs that function. JWT validation is tempting because it is an API Gateway security feature, but it addresses identity assurance, not abuse prevention.
- ✗
WAF integration
Why it's wrong here
A WAF inspects HTTP request content against rule sets to block injection, XSS and similar payload attacks; it does not count requests per client over time. Rate limiting or throttling is the feature that caps request volume to prevent abuse or DoS, so WAF integration would be correct if the requirement were filtering malicious request patterns.
- ✗
Mutual TLS
Why it's wrong here
Mutual TLS authenticates both client and server via certificates and encrypts the channel in transit; it does not meter request frequency. Throttling or rate limiting enforces a requests-per-interval quota per client to stop abuse or DoS. Mutual TLS would be correct if the requirement were verifying client identity or securing transport.
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.