CCSP Cloud Application Security Practice Question
Which THREE of the following are valid techniques to protect application programming interfaces (APIs) from abuse?
⚠ Common exam trap
A common mix-up: candidates think JWT without encryption is acceptable because JWTs are often signed (JWS), but the CCSP exam emphasizes that confidentiality is a separate requirement—signing alone does not protect sensitive data in the payload, and encryption (JWE) is mandatory when tokens contain private information.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use API gateways to enforce authentication and authorization policies.
Option A is correct because an API gateway acts as a centralized enforcement point where authentication (e.g., validating OAuth 2.0 tokens or mTLS client certificates) and authorization policies (e.g., scope or role checks) are applied before requests reach backend services, blocking unauthenticated or unauthorized abuse. Option D is correct because rate limiting and throttling cap the number of requests a client can make per time window (e.g., 100 requests/minute per API key), mitigating brute-force, credential-stuffing, scraping, and denial-of-service abuse. Option E is correct because requiring an API key or OAuth token on every request ensures each call is tied to an identifiable, revocable principal, enabling per-client quotas, auditing, and immediate revocation of compromised credentials. Option B is not a valid protection technique because an unencrypted JWT is only base64url-encoded and signed, not confidential—its payload can be read by anyone, so it does not protect the API from abuse and may leak sensitive claims. Option C is incorrect because restricting APIs to HTTP GET does not prevent abuse; GET requests can still be replayed, scraped, or flooded, and many legitimate operations require POST, PUT, or DELETE, so this neither authenticates nor limits callers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use API gateways to enforce authentication and authorization policies.
Why this is correct
An API gateway centralises authentication and authorisation enforcement at the ingress point, validating tokens and applying policy before requests reach backend services. This prevents unauthenticated or unauthorised callers from invoking APIs, directly countering abuse such as credential-less enumeration and privilege escalation.
- ✗
Use JSON Web Tokens (JWT) without encryption.
Why it's wrong here
JWTs should be signed and optionally encrypted; without encryption, payload is readable.
- ✗
Use only HTTP GET requests for all API calls.
Why it's wrong here
Restricting APIs to GET prevents state-changing operations but does nothing against abuse such as credential stuffing, scraping or replay, and GET parameters leak into logs. It is tempting because GET is idempotent and cacheable, suiting read-only public endpoints where no mutation occurs.
- ✓
Implement rate limiting and throttling.
Why this is correct
Rate limiting and throttling cap request volume per client or key within a time window, absorbing bursts and denying excess traffic. This mitigates abuse patterns including brute-force credential stuffing, scraping and denial-of-service, protecting backend APIs from resource exhaustion without blocking legitimate consumers.
- ✓
Require API keys or OAuth tokens for every request.
Why this is correct
Requiring an API key or OAuth token on every request forces caller identification and authorisation before processing, so anonymous or replayed calls are rejected. This establishes accountability and enables per-client policy enforcement, directly preventing unauthorised API abuse across the exposed surface.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.