Cloud Application Security Flashcards
7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cloud Application Security flashcards as text
Which methodology integrates security practices directly into the DevOps pipeline for cloud applications?
Answer: DevSecOps
DevSecOps embeds security checks and automation throughout the DevOps pipeline so vulnerabilities are caught early in the development lifecycle.
According to the CSA CCSK guidance, which phase of the Secure Software Development Lifecycle (SSDLC) should threat modeling occur?
Answer: Design
Threat modeling should be performed during the Design phase so that security requirements and mitigations are built into the architecture before code is written.
What is the primary purpose of a Web Application Firewall (WAF) deployed in front of a cloud-hosted application?
Answer: Filter and monitor HTTP/HTTPS traffic to block application-layer attacks
A WAF inspects HTTP/HTTPS traffic and blocks application-layer attacks such as SQL injection and cross-site scripting before they reach the application.
In cloud-native application development, which practice helps ensure that secrets such as API keys and database credentials are NOT hardcoded in source code?
Answer: Use of a secrets management service or vault
Secrets management services (e.g., HashiCorp Vault or cloud-native equivalents) store and inject credentials at runtime, preventing them from being embedded in source code.
Which OWASP resource specifically addresses the most critical security risks found in web applications and is commonly referenced in CCSK cloud application security?
Answer: OWASP Top 10
The OWASP Top 10 is the widely recognized list of the most critical web application security risks and is a key reference for cloud application security.
Static Application Security Testing (SAST) tools analyze an application to find vulnerabilities at which stage?
Answer: By examining source code or binaries without executing the program
SAST analyzes source code, bytecode, or binaries in a non-running state, enabling early detection of vulnerabilities before deployment.
In the context of cloud application security, what does the term 'shift left' mean?
Answer: Integrating security activities earlier in the development lifecycle
Shifting left means incorporating security testing and reviews earlier in the SDLC — during design and development — rather than waiting until testing or deployment.