Courseiva

CCSP Cloud Application Security Practice Question

Which THREE are key considerations when designing a secure software development lifecycle (SSDLC) for cloud applications?

⚠ Common exam trap

ISC2 often tests the distinction between activities that are part of the secure development lifecycle (design, code, test) versus operational security tasks (production testing), and candidates mistakenly select 'Security testing in production' because they confuse it with runtime security monitoring or penetration testing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Static code analysis during development

Static code analysis during development (A) is correct because SAST tools scan source code for vulnerabilities such as injection flaws and insecure API usage before deployment, shifting security left in the SSDLC. Threat modeling at the design phase (B) is correct because it identifies trust boundaries, data flows, and potential attack vectors (e.g., STRIDE) early, when architectural changes are cheapest to make. Secure coding standards (E) are correct because they give developers concrete, enforceable rules (e.g., OWASP ASVS, input validation, output encoding) that reduce the introduction of common vulnerabilities in cloud-native code. Security testing in production (C) is not a core SSDLC design consideration; while runtime monitoring and DAST may occur post-deployment, production testing is an operational activity rather than a lifecycle design principle. Using a single cloud provider (D) is irrelevant to SSDLC security design and may even increase lock-in and single-point-of-failure risk, so it is not a key consideration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Static code analysis during development

    Why this is correct

    Static code analysis scans source during development, catching injection flaws and insecure patterns before deployment. It satisfies the SSDLC requirement to embed security checks early in the build phase rather than relying on production controls.

  • ✓

    Threat modeling at design phase

    Why this is correct

    Threat modelling at design phase identifies trust boundaries, data flows and attack surfaces before code exists, letting architects mitigate risks cheaply. It satisfies the SSDLC requirement to address security during design rather than retrofitting later.

  • ✗

    Security testing in production

    Why it's wrong here

    Production testing happens after code is deployed, so it cannot gate releases within the SSDLC itself; the stem asks for design considerations covering build and deploy phases. It is tempting because runtime testing genuinely validates live behaviour, and would be right for continuous verification or incident validation, not lifecycle design.

  • ✗

    Using a single cloud provider

    Why it's wrong here

    Single-provider reliance is a commercial or resilience decision, not an SSDLC control; the stem asks for secure development considerations such as threat modelling, code review and dependency scanning. It tempts because provider consolidation simplifies identity and tooling, and would suit a small team standardising operations, not secure lifecycle design.

  • ✓

    Secure coding standards

    Why this is correct

    Secure coding standards give developers concrete, language-specific rules for avoiding injection, authentication and input-handling flaws, embedding security directly into the build phase rather than relying on later testing. This satisfies the SSDLC requirement for preventive, repeatable controls applied consistently across cloud application codebases.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.