CCSP Cloud Application Security Practice Question
Which THREE are key considerations when designing a secure software development lifecycle (SSDLC) for cloud applications?
⚠ Common exam trap
ISC2 often tests the distinction between activities that are part of the secure development lifecycle (design, code, test) versus operational security tasks (production testing), and candidates mistakenly select 'Security testing in production' because they confuse it with runtime security monitoring or penetration testing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Static code analysis during development
Static code analysis during development (A) is correct because SAST tools scan source code for vulnerabilities such as injection flaws and insecure API usage before deployment, shifting security left in the SSDLC. Threat modeling at the design phase (B) is correct because it identifies trust boundaries, data flows, and potential attack vectors (e.g., STRIDE) early, when architectural changes are cheapest to make. Secure coding standards (E) are correct because they give developers concrete, enforceable rules (e.g., OWASP ASVS, input validation, output encoding) that reduce the introduction of common vulnerabilities in cloud-native code. Security testing in production (C) is not a core SSDLC design consideration; while runtime monitoring and DAST may occur post-deployment, production testing is an operational activity rather than a lifecycle design principle. Using a single cloud provider (D) is irrelevant to SSDLC security design and may even increase lock-in and single-point-of-failure risk, so it is not a key consideration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Static code analysis during development
Why this is correct
Static code analysis scans source during development, catching injection flaws and insecure patterns before deployment. It satisfies the SSDLC requirement to embed security checks early in the build phase rather than relying on production controls.
- ✓
Threat modeling at design phase
Why this is correct
Threat modelling at design phase identifies trust boundaries, data flows and attack surfaces before code exists, letting architects mitigate risks cheaply. It satisfies the SSDLC requirement to address security during design rather than retrofitting later.
- ✗
Security testing in production
Why it's wrong here
Production testing happens after code is deployed, so it cannot gate releases within the SSDLC itself; the stem asks for design considerations covering build and deploy phases. It is tempting because runtime testing genuinely validates live behaviour, and would be right for continuous verification or incident validation, not lifecycle design.
- ✗
Using a single cloud provider
Why it's wrong here
Single-provider reliance is a commercial or resilience decision, not an SSDLC control; the stem asks for secure development considerations such as threat modelling, code review and dependency scanning. It tempts because provider consolidation simplifies identity and tooling, and would suit a small team standardising operations, not secure lifecycle design.
- ✓
Secure coding standards
Why this is correct
Secure coding standards give developers concrete, language-specific rules for avoiding injection, authentication and input-handling flaws, embedding security directly into the build phase rather than relying on later testing. This satisfies the SSDLC requirement for preventive, repeatable controls applied consistently across cloud application codebases.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.