Courseiva
Cloud Application Security →mediumMultiple Select

CCSP Cloud Application Security Practice Question

Which TWO practices help protect against insecure deserialization attacks in cloud applications?

⚠ Common exam trap

ISC2 often tests the misconception that encryption alone (Option B) is sufficient to secure serialized data, but encryption only protects data at rest or in transit, not the deserialization process itself, which is where the attack occurs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Validate serialized objects before deserialization

Option D is correct because validating serialized objects before deserialization ensures that the data being processed matches expected types, structures, and values, which prevents attackers from injecting malicious payloads that exploit deserialization logic. Option E is correct because restricting deserialization to a whitelist of allowed classes ensures that only pre-approved, safe classes can be instantiated, blocking gadget-chain attacks that rely on unexpected or dangerous classes. Option A is incorrect because allowing deserialization from untrusted sources directly enables insecure deserialization attacks. Option B is incorrect because strong encryption protects data confidentiality in transit or at rest but does not prevent malicious payloads from being deserialized after decryption. Option C is incorrect because implementing custom deserialization without validation removes the safety checks needed to reject malicious or unexpected objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow deserialization from untrusted sources

    Why it's wrong here

    Allowing deserialisation from untrusted sources is precisely the vulnerability, since attacker-controlled bytes can instantiate arbitrary objects and execute code. It is tempting when data crosses trust boundaries, but safe practise restricts deserialisation to trusted, validated sources.

  • ✗

    Use strong encryption for all serialized data

    Why it's wrong here

    Encryption protects serialized payloads in storage or transit, but deserialization attacks exploit the parser itself once data is decrypted and processed. The fix is type restrictions and allow-lists, not confidentiality. Encryption is genuinely useful for protecting sensitive data at rest or in transit, which is why it appears plausible here.

  • ✗

    Implement custom deserialization without validation

    Why it's wrong here

    Writing bespoke deserialization code without validation directly enables the vulnerability, since untrusted input constructs arbitrary objects. The correct practices are allow-listing permitted classes and integrity checks. Custom deserialisation is tempting when a legacy format lacks a safe library parser, but it must still validate types before instantiation.

  • ✓

    Validate serialized objects before deserialization

    Why this is correct

    Validating serialised objects before deserialisation rejects unexpected classes and malformed payloads, preventing gadget chains from executing during object reconstruction. This satisfies the stem's requirement for a practise that protects cloud applications against insecure deserialisation attacks.

  • ✓

    Restrict deserialization to a whitelist of classes

    Why this is correct

    Whitelisting permitted classes constrains deserialisation to known, expected types, preventing attackers from instantiating arbitrary classes that trigger malicious gadget chains. This directly satisfies the requirement to protect against insecure deserialisation by rejecting unexpected input during object reconstruction.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.