CCSP Cloud Application Security Practice Question
Which TWO of the following are primary objectives of a cloud application security program?
⚠ Common exam trap
ISC2 often tests the distinction between security objectives and operational or architectural practices, trapping candidates who confuse 'continuous deployment' or 'microservices' with security goals because they are commonly discussed in cloud security contexts but are not primary objectives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Maintaining application availability
Option A (Maintaining application availability) is correct because a cloud application security program must protect against denial-of-service, misconfiguration, and resilience failures so that applications remain accessible to authorized users, aligning with the availability pillar of the CIA triad. Option D (Ensuring data confidentiality and integrity) is correct because the core purpose of application security is to prevent unauthorized disclosure and unauthorized modification of data, typically enforced through encryption, access controls, and integrity checks. Options B (continuous deployment), C (microservices architecture), and E (Agile development practices) are incorrect because they are software delivery and architectural methodologies, not security objectives; they may support security when implemented well but are not primary goals of a cloud application security program.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Maintaining application availability
Why this is correct
Availability is a core security objective because a cloud application rendered unreachable effectively fails its security posture. Resilience, redundancy and DDoS mitigation preserve service continuity, satisfying the program's mandate to keep applications accessible to legitimate users.
- ✗
Performing continuous deployment
Why it's wrong here
Continuous deployment automates release pipelines, not application security; it neither identifies vulnerabilities nor enforces controls, so it cannot be a security programme objective. It is tempting because CI/CD pipelines often embed security scanning, but that scanning is the objective — deployment frequency is a DevOps delivery goal, relevant when the question asks about release velocity or operational efficiency.
- ✗
Implementing a microservices architecture
Why it's wrong here
Microservices architecture addresses application design and deployment granularity, not security programme objectives; it neither identifies controls nor manages risk. It is tempting because service isolation and independent scaling can shrink blast radius, and it would be the right answer if the question asked how to decompose a monolith for resilience or independent deployment.
- ✓
Ensuring data confidentiality and integrity
Why this is correct
Safeguarding data confidentiality and integrity directly satisfies the core objective of protecting information throughout its lifecycle in cloud environments. Encryption, access controls and integrity monitoring uphold these CIA triad pillars, which the stem identifies as primary goals of a cloud application security programme.
- ✗
Adopting Agile development practices
Why it's wrong here
Agile practices govern how development teams plan and iterate on work; they say nothing about securing the resulting application. Agile adoption belongs to delivery transformation initiatives, whereas a security programme targets risk reduction across the application lifecycle.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.