CCSP Cloud Application Security: 240 practice questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

CCSP Cloud Application Security: 240 practice questions

CCSP 240 questions 12 shown free

12 of the 240 Cloud Application Security questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for CCSP? Take the free 5-min readiness check →

1. Use DAST with authenticated: Which control directly addresses this demonstrated failure?

Medium
A logistics operator's cloud scanner found that a shipment API exposed another customer's record only when requests were executed against the deployed service. Which control directly addresses this demonstrated failure?
  1. Use DAST with authenticated, cross-tenant authorization tests. ✓
    DAST exercises running software and can verify whether requests improperly cross tenant authorization boundaries.
  2. Require a trusted signature on every deployment artifact.
    Artifact signatures establish provenance and integrity, not whether deployed application logic correctly enforces authorization.
  3. Generate an SBOM for the API's third-party packages.
    SCA and SBOM activities identify component exposure, but they do not directly test object authorization behavior.
  4. Run SAST on the API source before each deployment.
    SAST examines code without execution, so it may miss authorization behavior requiring deployed requests and realistic identities.
The trap
Confuses artifact integrity with application security. Addresses dependencies rather than demonstrated authorization failure. Confuses source inspection with runtime behavior testing.

DAST tests deployed behavior, making it appropriate for discovering runtime cross-tenant authorization failures.

2. Role-mapped records showing training completion: Which evidence best satisfies the requirement?

Medium
A media platform requires role-specific secure-development training. Before granting repository access, the security manager must verify both participation and practical understanding. Which evidence best satisfies the requirement?
  1. A general security-newsletter delivery report plus a current repository-access list.
    Distribution and access records do not demonstrate role-specific training or practical comprehension.
  2. Commit history containing secure coding changes and review comments.
    Repository activity may show behavior but does not prove completion of assigned role-specific training or assessment.
  3. Role-mapped records showing training completion, assessment results, and remediation. ✓
    These records establish applicability, participation, assessed understanding, and follow-up for failures.
  4. A manager's email asserting that developers understand secure coding.
    An assertion does not objectively establish assigned training completion or practical understanding.
The trap
Relies on unsupported attestation. Infers training from work output. Confuses communication and authorization records with learning evidence.

Role-mapped completion and assessment records verify both participation and understanding.

3. Document the requirement: What is the most appropriate remediation?

Hard
A digital payments company discovered during a control test that a payment-service design lacks a documented security requirement for server-side authorization. The service is not yet deployed. What is the most appropriate remediation?
  1. Document the requirement, update the design, and retest authorization before release. ✓
    This remediation restores traceability, incorporates security before deployment, and verifies the control through a repeat test.
  2. Sign the existing artifact and record the failed test as accepted risk.
    Signing protects provenance and integrity, while risk acceptance does not satisfy an unmet authorization requirement before release.
  3. Deploy first, then use production monitoring to detect unauthorized access.
    Monitoring may detect consequences, but it does not remediate the missing requirement or prevent an avoidable release defect.
  4. Replace the payment service with a network firewall rule restricting its endpoint.
    Network filtering can restrict connectivity, but it cannot enforce authorization for individual payment objects or actions.
The trap
Applies perimeter control to application authorization. Defers prevention until after deployment. Treats approval evidence as corrective engineering.

The failed test requires a traced requirement, corrected design, and verification before deployment.

4. It supports signer authenticity and artifact integrity: What security conclusion does a successfully validated

Easy
An industrial manufacturer requires signed build artifacts. What security conclusion does a successfully validated signature support?
  1. It guarantees the deployed application cannot be compromised through runtime weaknesses.
    Runtime configuration, credentials, dependencies, and application vulnerabilities can still enable compromise.
  2. It proves the artifact has no exploitable vulnerabilities.
    Signature validation does not assess code logic, dependencies, configuration, or vulnerabilities.
  3. It proves every dependency received security approval before inclusion.
    Dependency approval requires separate inventory and review evidence.
  4. It supports signer authenticity and artifact integrity, but not software safety. ✓
    A trusted signature links the artifact to a signer and detects alteration after signing, but does not prove the artifact is harmless.
The trap
Confuses integrity with safety. Assumes signing includes dependency governance. Treats artifact integrity as complete runtime protection.

A valid signature supports provenance and integrity, not absence of vulnerabilities or malware.

5. The relying service’s application owner: Who owns that decision?

Medium
A legal services firm federates workforce access to a cloud case system. The identity provider issues signed assertions, but the firm must decide whether the service should accept them and what permissions accepted identities receive. Who owns that decision?
  1. The certificate issuer that supports the assertion signature.
    A certificate issuer supports cryptographic trust infrastructure but does not decide whether the firm accepts assertions or grants application permissions.
  2. The relying service’s application owner, under documented federation and authorization policy. ✓
    The application owner governs relying-party acceptance and applies the service’s local authorization policy after validating the assertion.
  3. The user whose employment account is identified.
    The user is the subject of the assertion, not the authority that configures relying-party trust or authorization policy.
  4. The network administrator responsible for the firm’s perimeter firewall rules.
    Firewall rules govern network traffic and do not determine federation trust or application entitlements.
The trap
Assigns governance authority to the identity subject. Confuses certificate trust with business authorization. Confuses network administration with identity and authorization governance.

The relying service owner decides assertion acceptance and resulting application permissions.

6. The application must enforce server-side authorization: Which responsibility boundary is correct?

Medium
A distributed engineering team uses a WAF in front of an API. A test shows an authenticated user can change another user's invoice by altering an object identifier. Which responsibility boundary is correct?
  1. The container host should block requests containing modified invoice identifiers.
    Host isolation protects runtime infrastructure, but cannot reliably interpret business ownership or permitted invoice actions.
  2. A network firewall should permit only the user's original invoice identifier.
    Network firewalls filter connection attributes and cannot maintain application-specific object authorization decisions.
  3. The WAF should decide whether the requested invoice belongs to the caller.
    A WAF can inspect web requests, but business ownership and object-level permission decisions belong inside application authorization.
  4. The application must enforce server-side authorization for each object and action. ✓
    The application has the necessary identity, object, and action context to enforce authorization for each request.
The trap
Assigns business authorization to perimeter filtering. Confuses infrastructure isolation with business policy. Uses network filtering for object-level policy.

Object ownership and action permissions require server-side application authorization, not WAF or network filtering.

7. Model the boundary: Which approach best satisfies the stated requirements?

Medium
A public agency permits limited user-authored HTML for accessibility and requires service to continue during a filtering failure. A STRIDE review identifies untrusted content entering browser-rendered pages. Which approach best satisfies the stated requirements?
  1. Validate input syntax and rely on a permissive CSP when filtering is unavailable, without changing rendering logic.
    Input validation and CSP do not substitute for maintained sanitization and context-specific output encoding.
  2. Reject all user-authored content during every filtering outage.
    This may reduce exposure but violates the stated availability and permitted-content requirements.
  3. Model the boundary, sanitize permitted HTML, encode output by context, and define degraded operation. ✓
    This addresses the browser trust-boundary crossing while preserving approved content and planning for filter failure.
  4. Use a WAF as the sole control for malicious browser content.
    A WAF is defense in depth and cannot replace context-appropriate encoding and sanitization.
The trap
Solves security by abandoning required functionality. Treats perimeter filtering as complete XSS prevention. Combines incomplete controls while ignoring rendering context.

Use trust-boundary analysis, HTML sanitization, contextual encoding, and an explicit degraded mode.

8. Record the flaw: Which evidence qualifies?

Easy
A biotechnology laboratory permits a dependency exception only if the vulnerability is documented, compensating controls are tested, a business owner accepts residual risk, and an expiration date is recorded. Which evidence qualifies?
  1. A scanner screenshot identifying the vulnerability.
    Detection alone does not document tested controls, approval, or expiration.
  2. A developer's note that the vulnerable function is rarely used.
    The note does not establish tested compensating controls, accountable approval, or an expiration date.
  3. An SBOM listing the affected dependency and version.
    An SBOM supplies inventory but not mitigation testing, risk acceptance, or time limits.
  4. Record the flaw, tested mitigation, owner approval, and expiry. ✓
    This evidence addresses all four conditions in the exception policy.
The trap
Confuses identification with exception authorization. Confuses inventory with governance. Relies on informal justification.

A valid exception record covers the flaw, tested mitigation, accountable approval, and expiry.

9. Training does not itself enforce authorization for each: Which statement is correct?

Medium
A financial services firm's developer training explains API authentication and warns about object-level authorization. The firm asks what limitation remains after training completion. Which statement is correct?
  1. Training proves every API endpoint has been dynamically tested.
    Completion evidence does not demonstrate runtime test coverage, endpoint behavior, or authorization results.
  2. Training does not itself enforce authorization for each requested object and action. ✓
    Awareness can guide developers, but server-side application logic must enforce object and action authorization.
  3. Training automatically causes the identity provider to issue stronger credentials.
    Training changes knowledge, not identity-provider credential strength or authentication-factor properties.
  4. Training eliminates the need for authorization logs and entitlement reviews.
    Training does not replace operational evidence, lifecycle management, monitoring, or periodic entitlement review.
The trap
Confuses education with credential control. Confuses learning evidence with technical verification. Treats awareness as a complete governance control.

Developer awareness cannot enforce runtime permissions; application logic and verification remain necessary.

10. Add a testable security criterion and require evidence: What should the product owner require?

Medium
An international nonprofit records: “Story complete means code merged; security review is optional.” Policy requires security acceptance criteria for sensitive data flows before release. What should the product owner require?
  1. Add a generic security note to the backlog.
    A generic note lacks testable evidence and does not establish that the sensitive flow passed review.
  2. Leave the definition unchanged and monitor the first production release.
    Postrelease monitoring cannot satisfy a requirement for security acceptance before release.
  3. Add a testable security criterion and require evidence before release. ✓
    This makes the policy requirement part of completion and requires verifiable evidence before release.
  4. Require a signed artifact as the release evidence.
    A signature supports integrity and provenance, but does not verify the required security acceptance criterion.
The trap
Records intent without an auditable completion condition. Substitutes provenance evidence for security acceptance. Defers a required preventive decision until production.

Security acceptance must be testable, evidenced, and required before release.

11. Correlate listed components with vulnerabilities: Which action is most appropriate?

Easy
A training company has generated an SBOM for its cloud learning application. The development team confirms the inventory is complete, but no component vulnerabilities have yet been assessed. Management asks for the next action that addresses the SBOM’s limitation without treating inventory as remediation. Which action is most appropriate?
  1. Replace the application with a newly signed artifact.
    Signing establishes artifact integrity and provenance, but it does not assess or remediate vulnerable listed components.
  2. Correlate listed components with vulnerabilities and prioritize remediation. ✓
    SBOMs inventory components; vulnerability correlation and remediation activities address the resulting security exposure.
  3. Require users to complete multifactor authentication before deployment.
    Multifactor authentication protects access, but it does not resolve unidentified or vulnerable software dependencies.
  4. Move the application behind a web application firewall.
    A WAF can provide defense in depth, but it cannot replace component assessment and remediation.
The trap
Integrity evidence does not evaluate component vulnerabilities. Access control does not remediate dependency flaws. Perimeter filtering cannot inventory or repair libraries.

An SBOM identifies components; separate assessment and remediation are required to address their vulnerabilities.

12. Require independent MFA for privileged federation: Which gap should the security lead address first?

Medium
A university research consortium uses federation across cloud services. Researchers have one sign-in, but the identity provider requires only a password. Policy requires an independent second factor for privileged research administration. Which gap should the security lead address first?
  1. Review authorization roles across every research application.
    Role review may address excessive permissions, but it does not correct password-only authentication.
  2. Protect identity-provider key-encryption keys with stronger encryption.
    Key protection may support cryptographic security but cannot add a missing authentication factor.
  3. Replace federation with local accounts and passwords.
    Moving accounts does not inherently add an independent authentication factor.
  4. Require independent MFA for privileged federation. ✓
    This directly addresses the password-only gap while retaining federation and requiring the policy-mandated second factor.
The trap
Confuses account location with authentication strength. Confuses authorization review with multifactor authentication. Confuses cryptographic key protection with user authentication.

Federation and SSO do not provide the required independent second factor.

228 more Cloud Application Security questions

The remaining 228 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your CCSP readiness — free

Other CCSP domains

Part of the Certsqill CCSP question bank · Cloud Application Security · Every answer, right and wrong, comes with its own explanation.