SSCP Systems and Application Security Practice Question
A financial services firm runs a Java-based customer portal on Apache Tomcat. During a code review, the security team discovers that the application deserializes session objects received from an untrusted partner API without validating their contents. An attacker could craft a malicious serialized object that executes arbitrary code on the server when deserialized. Which of the following controls BEST mitigates this risk?
⚠ Common exam trap
The trap here is assuming that encrypting the transport channel with mutual TLS secures the payload, when in fact it only protects data in transit and does nothing to validate the deserialized object itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a strict allowlist of permitted classes for deserialization and reject all others.
Insecure deserialization allows attackers to influence object state and potentially achieve remote code execution. The most direct fix is to constrain which classes can be deserialized using an allowlist, so only expected types from the partner API are accepted. Transport encryption, WAF rules, and JVM tuning do not validate object contents and therefore fail to eliminate the vulnerability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable TLS 1.3 with mutual authentication between the portal and the partner API.
Why it's wrong here
Mutual TLS encrypts and authenticates the transport channel, but the partner API is already a trusted endpoint. The malicious object originates from a compromised or malicious partner, so it would still pass transport authentication. TLS does not inspect or validate the serialized object payload, leaving the deserialization vulnerability exploitable.
- ✓
Implement a strict allowlist of permitted classes for deserialization and reject all others.
Why this is correct
An allowlist restricts deserialization to only known, safe classes, preventing attacker-controlled gadget chains from being instantiated. Because the partner API only needs to send specific session object types, enumerating those types and rejecting everything else directly blocks the malicious object from being processed. This is the most targeted and effective mitigation for insecure deserialization in this scenario.
- ✗
Increase the Java heap size and enable garbage collection tuning on the Tomcat server.
Why it's wrong here
Heap size and garbage collection tuning affect performance and memory management, not code execution risk. A malicious deserialized object will still be instantiated and executed regardless of heap configuration. This option addresses availability rather than the integrity and confidentiality threats posed by insecure deserialization.
- ✗
Deploy a web application firewall (WAF) with OWASP ModSecurity Core Rule Set in blocking mode.
Why it's wrong here
A WAF can detect some known serialized payload signatures, but it cannot reliably parse and validate arbitrary Java serialization streams. Attackers can obfuscate or encode malicious objects to bypass signature-based rules. A WAF provides defense in depth but does not address the root cause of deserializing untrusted classes, so it is not the best mitigation.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.