CCSP Cloud Application Security Practice Question
Which THREE of the following are common challenges in securing serverless applications?
⚠ Common exam trap
ISC2 often tests the misconception that serverless eliminates all infrastructure security concerns, leading candidates to overlook the critical need for input validation and dependency management, while incorrectly assuming that network controls like firewalls are still applicable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Insecure handling of event source inputs
Option B is correct because serverless functions are triggered by diverse event sources (API Gateway, S3, SNS, SQS, etc.), and failing to validate or sanitize these inputs exposes functions to injection and event-injection attacks. Option C is correct because serverless deployments rely heavily on third-party packages and runtime dependencies, so vulnerable or outdated libraries become a primary risk since providers do not patch application code. Option D is correct because decomposing an application into many small functions multiplies entry points and triggers, enlarging the attack surface that must be individually secured and monitored. Option A is not a distinguishing serverless challenge since the provider manages the kernel and OS, removing that control burden from the customer. Option E is not applicable because serverless architectures are inherently stateless and typically rely on security groups, IAM, and WAF rather than stateful firewall rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Lack of control over the underlying kernel and OS
Why it's wrong here
Serverless platforms abstract the kernel and OS, so providers patch and harden them; tenants cannot access or control that layer regardless. This is a shared-responsibility consequence rather than a challenge, since the abstraction removes the burden instead of creating a security gap to manage.
- ✓
Insecure handling of event source inputs
Why this is correct
Event source inputs reach functions as untrusted payloads from queues, buckets, HTTP triggers or databases. Without validation and sanitisation, injection and malformed-data attacks succeed, making insecure handling of event source inputs a genuine serverless security challenge.
- ✓
Vulnerabilities in third-party libraries and dependencies
Why this is correct
Serverless functions bundle third-party packages into each deployment, so a flaw in any transitive dependency ships directly into production. This satisfies the stem's challenge of securing serverless applications, where patching requires rebuilding and redeploying every affected function rather than updating a shared runtime.
- ✓
Increased attack surface due to many small functions
Why this is correct
Decomposing an application into many small functions multiplies entry points, triggers, permissions and integrations. Each function is an independently attackable surface, so the aggregate attack surface grows substantially compared with a monolithic deployment, making this a recognised serverless challenge.
- ✗
Difficulty in applying stateful firewall rules
Why it's wrong here
Serverless functions are invoked per event and are inherently stateless, so connection-oriented stateful inspection is not the model; controls apply per invocation or at the API gateway. Stateful firewall rules suit long-lived VM or network-perimeter traffic, making this a mismatch with the execution model.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.