Courseiva

CCSP Cloud Application Security Practice Question

Which TWO best practices help secure a cloud application's runtime environment?

⚠ Common exam trap

ISC2 often tests the distinction between security controls that are preventive (like immutable infrastructure and least privilege) versus detective or reactive controls (like HIDS), leading candidates to mistakenly select host-based intrusion detection as a runtime security best practice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use immutable infrastructure

Option A (Use immutable infrastructure) is correct because replacing rather than modifying running instances eliminates configuration drift and prevents attackers from persisting changes on a compromised host, since any tampering is discarded when the instance is rebuilt from a known-good image. Option C (Run applications with least privilege) is correct because granting each process, service account, and container only the minimum permissions it needs limits the blast radius of a compromise and blocks privilege-escalation paths within the runtime environment. Option B (host-based intrusion detection) is a detective control that can complement runtime security but does not itself harden or secure the environment, and it is often impractical in ephemeral cloud workloads. Option D (automatic patching of dependencies) addresses vulnerability management in the build/supply chain rather than securing the runtime environment itself, and blind auto-patching can introduce instability. Option E (container orchestration platform) is a deployment technology, not a security best practice, and using it without proper configuration can actually widen the attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use immutable infrastructure

    Why this is correct

    Immutable infrastructure replaces running instances rather than patching them in place, so configuration drift and persistent compromise are eliminated on each deployment. This satisfies the runtime security requirement by ensuring every instance starts from a known, verified image.

  • ✗

    Implement host-based intrusion detection

    Why it's wrong here

    Host-based intrusion detection monitors a single server's internals, which is ineffective when containers and serverless instances are ephemeral and replaced constantly. It remains valid for long-lived virtual machines; runtime protection for cloud-native workloads instead relies on image scanning, immutable infrastructure and platform-level monitoring.

  • ✓

    Run applications with least privilege

    Why this is correct

    Least privilege grants each application and service identity only the permissions its function requires, limiting blast radius if credentials are compromised. This satisfies the runtime security requirement by constraining what an attacker can reach from a compromised workload.

  • ✗

    Enable automatic patching of dependencies

    Why it's wrong here

    Automatic dependency patching alone does not secure the runtime environment; it addresses library vulnerabilities but leaves runtime hardening, least-privilege execution and monitoring unaddressed. It is a valid supply-chain control, yet the question asks for runtime protection, where workload-level controls such as runtime application self-protection apply.

  • ✗

    Use container orchestration platform

    Why it's wrong here

    Orchestration platforms schedule and scale containers; they do not by themselves secure the runtime, and misconfiguration is a common exposure. They are the right answer when the question asks how to deploy and manage containerised workloads, not which practices harden a running application.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.