Courseiva
easyMultiple Choice

CCSP Practice Question: Which cloud-specific vulnerability involves an…

Which cloud-specific vulnerability involves an attacker making a server-side request to the cloud metadata endpoint (e.g., 169.254.169.254) to retrieve temporary credentials?

⚠ Common exam trap

CCSP often tests the misconception that SSRF is only about accessing internal web servers, but in cloud environments, the metadata endpoint is the most critical target because it can yield credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) is a vulnerability where an attacker can manipulate a server to make HTTP requests to arbitrary destinations, including the cloud metadata endpoint at 169.254.169.254. By exploiting SSRF, an attacker can retrieve temporary credentials associated with the instance's IAM role, leading to cloud account compromise. This is a cloud-specific risk because the metadata endpoint is unique to cloud environments and is a common target for SSRF attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Server-Side Request Forgery (SSRF)

    Why this is correct

    SSRF lets an attacker induce the server to request the link-local metadata endpoint 169.254.169.254, which returns instance-role temporary credentials. This cloud-specific vulnerability satisfies the stem precisely: the metadata service is reachable only from the instance, so the server becomes the credential-theft proxy.

  • ✗

    Cross-Site Scripting (XSS)

    Why it's wrong here

    XSS involves injecting client-side scripts, not accessing metadata endpoints.

  • ✗

    Broken Object Level Authorization (BOLA)

    Why it's wrong here

    BOLA concerns APIs failing to verify that a caller owns the object referenced by an identifier, so it grants access to other users' data rather than issuing a server-side request to 169.254.169.254. It is tempting because BOLA also abuses trusted credentials, but it exploits missing per-object authorisation checks, not metadata endpoint reachability.

  • ✗

    SQL Injection

    Why it's wrong here

    SQL Injection manipulates database queries through unsanitised input, so it cannot cause the application server to fetch credentials from the link-local metadata address. It is tempting because both flaws stem from unvalidated input, but SQLi targets the database layer, whereas SSRF targets the instance metadata service on 169.254.169.254.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.