hardMultiple Choice
SSCP Practice Question: A financial services organization deploys a new…
A financial services organization deploys a new web application that allows customers to check account balances and transfer funds. The application uses a RESTful API with JSON payloads. Shortly after deployment, the security team notices unusual traffic patterns: many requests contain excessively long JSON strings in the 'amount' field, and some of these requests return 500 Internal Server Errors. The application logs show that these requests cause high CPU usage on the application server. The developers confirm that the input validation only checks for negative numbers and characters. Which type of attack is most likely occurring, and what is the best immediate mitigation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The attack is a Denial of Service using large payloads; implement input size limits and validation.
The symptoms indicate a Denial of Service attack via large payloads that consume server resources. Excessive JSON string length in the 'amount' field causes high CPU usage during parsing and processing, leading to 500 errors. The best immediate mitigation is to implement input size limits and strict validation to reject oversized payloads. Option A is incorrect because brute-force attacks typically involve repeated attempts with different values, not large payloads causing CPU exhaustion; rate limiting would not address the root cause. Option B is incorrect because cross-site scripting (XSS) targets client-side script execution in the browser, not server-side CPU spikes. Option D is incorrect because SQL injection would likely return database error messages or cause data manipulation, not high CPU from JSON parsing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The attack is a brute-force attempt on the amount field; implement rate limiting.
Why it's wrong here
Brute-force attacks repeatedly guess credentials or values; here a single oversized 'amount' payload triggers high CPU and 500 errors, indicating resource exhaustion rather than repeated guessing. Rate limiting would be correct against credential-stuffing or enumeration attempts, not a single malformed request.
- ✗
The attack is cross-site scripting; sanitize output.
Why it's wrong here
Cross-site scripting targets browser-side script execution in reflected or stored output; the oversized JSON 'amount' values causing 500 errors and high CPU indicate resource exhaustion from unbounded input, not script injection. Output sanitisation addresses XSS, not payload size limits.
- ✓
The attack is a Denial of Service using large payloads; implement input size limits and validation.
Why this is correct
Oversized JSON payloads consuming CPU and triggering 500 errors indicate resource exhaustion via large request bodies, not injection. Enforcing input size limits and strict validation caps the 'amount' field, preventing the server from processing payloads that exhaust CPU, satisfying the need to stop the attack immediately.
- ✗
The attack is SQL injection; use parameterized queries.
Why it's wrong here
SQL injection requires attacker-controlled SQL syntax reaching a database query; the oversized JSON strings and CPU exhaustion point to resource consumption from unbounded input, not query manipulation. Parameterised queries would be correct if the logs showed malformed SQL or database errors.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.