CCSP Cloud Application Security Practice Question
Which TWO practices help protect against insecure deserialization attacks in cloud applications?
⚠ Common exam trap
ISC2 often tests the misconception that encryption alone (Option B) is sufficient to secure serialized data, but encryption only protects data at rest or in transit, not the deserialization process itself, which is where the attack occurs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validate serialized objects before deserialization
Option D is correct because validating serialized objects before deserialization ensures that the data being processed matches expected types, structures, and values, which prevents attackers from injecting malicious payloads that exploit deserialization logic. Option E is correct because restricting deserialization to a whitelist of allowed classes ensures that only pre-approved, safe classes can be instantiated, blocking gadget-chain attacks that rely on unexpected or dangerous classes. Option A is incorrect because allowing deserialization from untrusted sources directly enables insecure deserialization attacks. Option B is incorrect because strong encryption protects data confidentiality in transit or at rest but does not prevent malicious payloads from being deserialized after decryption. Option C is incorrect because implementing custom deserialization without validation removes the safety checks needed to reject malicious or unexpected objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow deserialization from untrusted sources
Why it's wrong here
Allowing deserialisation from untrusted sources is precisely the vulnerability, since attacker-controlled bytes can instantiate arbitrary objects and execute code. It is tempting when data crosses trust boundaries, but safe practise restricts deserialisation to trusted, validated sources.
- ✗
Use strong encryption for all serialized data
Why it's wrong here
Encryption protects serialized payloads in storage or transit, but deserialization attacks exploit the parser itself once data is decrypted and processed. The fix is type restrictions and allow-lists, not confidentiality. Encryption is genuinely useful for protecting sensitive data at rest or in transit, which is why it appears plausible here.
- ✗
Implement custom deserialization without validation
Why it's wrong here
Writing bespoke deserialization code without validation directly enables the vulnerability, since untrusted input constructs arbitrary objects. The correct practices are allow-listing permitted classes and integrity checks. Custom deserialisation is tempting when a legacy format lacks a safe library parser, but it must still validate types before instantiation.
- ✓
Validate serialized objects before deserialization
Why this is correct
Validating serialised objects before deserialisation rejects unexpected classes and malformed payloads, preventing gadget chains from executing during object reconstruction. This satisfies the stem's requirement for a practise that protects cloud applications against insecure deserialisation attacks.
- ✓
Restrict deserialization to a whitelist of classes
Why this is correct
Whitelisting permitted classes constrains deserialisation to known, expected types, preventing attackers from instantiating arbitrary classes that trigger malicious gadget chains. This directly satisfies the requirement to protect against insecure deserialisation by rejecting unexpected input during object reconstruction.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.