← All CCSK Flashcard Decks

Cloud Application Security Flashcards

7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cloud Application Security flashcards as text
  1. Which security concern is most critical when exposing microservices through a public API in a cloud environment?

    Answer: Lack of proper authentication and authorization controls on API endpoints

    Without strong authentication and authorization controls, unauthorized actors can access or abuse API endpoints, making this the most critical security concern for public APIs.

  2. What is the role of an API Gateway in a cloud-native application architecture from a security perspective?

    Answer: It provides a centralized enforcement point for authentication, rate limiting, and traffic inspection

    An API Gateway acts as a centralized control point that enforces authentication, rate limiting, logging, and policy-based access across all API calls.

  3. Which vulnerability occurs when a cloud application includes functionality that allows attackers to enumerate and access other users' object references (e.g., user IDs, file names) in API requests?

    Answer: Insecure Direct Object Reference (IDOR) / BOLA

    Broken Object Level Authorization (BOLA), also known as IDOR, occurs when an API exposes object identifiers that attackers can manipulate to access other users' data.

  4. In container security for cloud applications, which practice reduces the attack surface of a running container?

    Answer: Using minimal base images and removing unnecessary packages

    Minimal base images reduce the number of installed packages and therefore the attack surface, limiting the tools available to an attacker who compromises the container.

  5. What is the primary security risk of using third-party or open-source libraries in cloud-deployed applications?

    Answer: They may contain known vulnerabilities that are inherited by the application (supply chain risk)

    Open-source and third-party dependencies can introduce known vulnerabilities into an application's supply chain, which attackers can exploit if libraries are not kept patched.

  6. Dynamic Application Security Testing (DAST) differs from SAST in that DAST:

    Answer: Tests the application while it is running by sending crafted inputs and observing responses

    DAST tools interact with a running application — simulating external attacks — making it effective at discovering runtime vulnerabilities that static analysis may miss.

  7. Which cloud application security control helps prevent Cross-Site Request Forgery (CSRF) attacks?

    Answer: Anti-CSRF tokens in state-changing requests

    Anti-CSRF tokens are unique, unpredictable values embedded in forms and verified server-side, preventing attackers from tricking users into submitting unauthorized requests.