TechNuggets Academy

Cloud Application Security

Free ISC2 Certified Cloud Security Professional (CCSP) practice — 6 questions on Cloud Application Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Cloud Application Security
A cloud-native application running on IaaS instances allows users to submit URLs for automated image processing. An attacker submits a URL pointing to http://169.254.169.254/latest/meta-data/iam/security-credentials/ and successfully retrieves the instance's temporary IAM credentials through the application's server-side fetch function. Which control BEST prevents this class of attack?
This is a Server-Side Request Forgery (SSRF) attack against the cloud instance metadata service. IMDSv2 requires a session token obtained via a PUT request with a hop-limited header, which simple GET-based SSRF payloads (like the one triggered through the URL-fetching feature) cannot satisfy, effectively blocking credential theft via the metadata endpoint.
Question 2 of 6 · Cloud Application Security
A security team receives a compiled, third-party microservice binary with no source code, no build access, and no cooperation from the vendor for instrumentation. The service is slated for production deployment in the organization's cloud environment. Which testing approach is MOST appropriate given these constraints?
DAST performs black-box testing by interacting with the running application over its exposed interfaces, requiring no source code, build artifacts, or internal instrumentation, which fits this vendor-supplied binary scenario exactly.
Question 3 of 6 · Cloud Application Security
A cloud application must allow a mobile app to authenticate end users and obtain a lightweight, JSON-based identity token to call a RESTful backend API, while minimizing parsing overhead on constrained mobile devices. Which identity federation standard is BEST suited to this requirement?
OpenID Connect is built on top of OAuth 2.0 and issues JSON Web Tokens (JWTs), which are compact and lightweight compared to XML-based assertions, making it the standard choice for mobile and REST API authentication scenarios.
Question 4 of 6 · Cloud Application Security
During an architecture review, a CCSP notes that a cloud application's OAuth 2.0 authorization server issues refresh tokens that never expire and are never invalidated after use. Which configuration change BEST reduces the risk of long-term token compromise?
Refresh token rotation invalidates each token immediately after it is used to obtain a new one, meaning a stolen refresh token becomes useless after a single use and triggers reuse-detection alerts if replayed, directly mitigating long-term compromise risk.
Question 5 of 6 · Cloud Application Security
Which statement BEST distinguishes an application sandbox from application virtualization in cloud application security architecture?
A sandbox (e.g., seccomp profiles, browser sandboxes) constrains what system calls, files, or network resources a running process can touch, whereas application virtualization (e.g., App-V style packaging, containerization) abstracts the app from the host OS for portability and dependency isolation, and the two serve different but complementary purposes.
Question 6 of 6 · Cloud Application Security
A development team's CI/CD pipeline was configured to fall back to a public package repository when the internal private package registry was temporarily unreachable. During that outage, malicious packages using the same names as internal libraries were pulled from the public repository and executed during the build. Which control would have BEST prevented this dependency confusion attack?
Dependency confusion attacks exploit ambiguous package resolution logic that allows a build tool to fetch a same-named package from a public registry instead of the intended private one; explicitly scoping package resolution to internal namespaces and disabling public fallback eliminates this ambiguity entirely.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →