← All CCSK Flashcard Decks

Cloud Application Security Flashcards

7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cloud Application Security flashcards as text
  1. Which methodology integrates security practices directly into the DevOps pipeline for cloud applications?

    Answer: DevSecOps

    DevSecOps embeds security checks and automation throughout the DevOps pipeline so vulnerabilities are caught early in the development lifecycle.

  2. According to the CSA CCSK guidance, which phase of the Secure Software Development Lifecycle (SSDLC) should threat modeling occur?

    Answer: Design

    Threat modeling should be performed during the Design phase so that security requirements and mitigations are built into the architecture before code is written.

  3. What is the primary purpose of a Web Application Firewall (WAF) deployed in front of a cloud-hosted application?

    Answer: Filter and monitor HTTP/HTTPS traffic to block application-layer attacks

    A WAF inspects HTTP/HTTPS traffic and blocks application-layer attacks such as SQL injection and cross-site scripting before they reach the application.

  4. In cloud-native application development, which practice helps ensure that secrets such as API keys and database credentials are NOT hardcoded in source code?

    Answer: Use of a secrets management service or vault

    Secrets management services (e.g., HashiCorp Vault or cloud-native equivalents) store and inject credentials at runtime, preventing them from being embedded in source code.

  5. Which OWASP resource specifically addresses the most critical security risks found in web applications and is commonly referenced in CCSK cloud application security?

    Answer: OWASP Top 10

    The OWASP Top 10 is the widely recognized list of the most critical web application security risks and is a key reference for cloud application security.

  6. Static Application Security Testing (SAST) tools analyze an application to find vulnerabilities at which stage?

    Answer: By examining source code or binaries without executing the program

    SAST analyzes source code, bytecode, or binaries in a non-running state, enabling early detection of vulnerabilities before deployment.

  7. In the context of cloud application security, what does the term 'shift left' mean?

    Answer: Integrating security activities earlier in the development lifecycle

    Shifting left means incorporating security testing and reviews earlier in the SDLC — during design and development — rather than waiting until testing or deployment.