Courseiva
Cloud Application Security →mediumMultiple Select

CCSP Cloud Application Security Practice Question

Which THREE of the following are common challenges in securing serverless applications?

⚠ Common exam trap

ISC2 often tests the misconception that serverless eliminates all infrastructure security concerns, leading candidates to overlook the critical need for input validation and dependency management, while incorrectly assuming that network controls like firewalls are still applicable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Insecure handling of event source inputs

Option B is correct because serverless functions are triggered by diverse event sources (API Gateway, S3, SNS, SQS, etc.), and failing to validate or sanitize these inputs exposes functions to injection and event-injection attacks. Option C is correct because serverless deployments rely heavily on third-party packages and runtime dependencies, so vulnerable or outdated libraries become a primary risk since providers do not patch application code. Option D is correct because decomposing an application into many small functions multiplies entry points and triggers, enlarging the attack surface that must be individually secured and monitored. Option A is not a distinguishing serverless challenge since the provider manages the kernel and OS, removing that control burden from the customer. Option E is not applicable because serverless architectures are inherently stateless and typically rely on security groups, IAM, and WAF rather than stateful firewall rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Lack of control over the underlying kernel and OS

    Why it's wrong here

    Serverless platforms abstract the kernel and OS, so providers patch and harden them; tenants cannot access or control that layer regardless. This is a shared-responsibility consequence rather than a challenge, since the abstraction removes the burden instead of creating a security gap to manage.

  • ✓

    Insecure handling of event source inputs

    Why this is correct

    Event source inputs reach functions as untrusted payloads from queues, buckets, HTTP triggers or databases. Without validation and sanitisation, injection and malformed-data attacks succeed, making insecure handling of event source inputs a genuine serverless security challenge.

  • ✓

    Vulnerabilities in third-party libraries and dependencies

    Why this is correct

    Serverless functions bundle third-party packages into each deployment, so a flaw in any transitive dependency ships directly into production. This satisfies the stem's challenge of securing serverless applications, where patching requires rebuilding and redeploying every affected function rather than updating a shared runtime.

  • ✓

    Increased attack surface due to many small functions

    Why this is correct

    Decomposing an application into many small functions multiplies entry points, triggers, permissions and integrations. Each function is an independently attackable surface, so the aggregate attack surface grows substantially compared with a monolithic deployment, making this a recognised serverless challenge.

  • ✗

    Difficulty in applying stateful firewall rules

    Why it's wrong here

    Serverless functions are invoked per event and are inherently stateless, so connection-oriented stateful inspection is not the model; controls apply per invocation or at the API gateway. Stateful firewall rules suit long-lived VM or network-perimeter traffic, making this a mismatch with the execution model.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.