Cloud Application Security Flashcards
6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Application Security flashcards as text
What is the primary risk of storing sensitive data in JWT (JSON Web Token) payloads?
Answer: JWT payloads are base64-encoded but not encrypted by default, making the data readable if intercepted
JWT payloads are only base64url-encoded, not encrypted, so anyone who intercepts or decodes the token can read the claims within it.
In a microservices architecture, what is mutual TLS (mTLS) used for?
Answer: Authenticating both the client and server to each other in service-to-service communication
mTLS requires both communicating parties to present certificates, ensuring that each microservice can verify the identity of the other before exchanging data.
Which threat modeling framework uses the mnemonic STRIDE to categorize threats?
Answer: Microsoft STRIDE model
Microsoft's STRIDE model categorizes threats as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
What is a major security concern with serverless (FaaS) applications in the cloud?
Answer: Insecure function triggers and over-permissive IAM roles granting excessive access
Serverless functions are often granted overly broad IAM permissions and may be triggered by insecure event sources, creating privilege escalation and injection risks.
What is the purpose of an API gateway in cloud application security?
Answer: To enforce authentication, rate limiting, and traffic management for API calls
An API gateway centralizes authentication, authorization, rate limiting, and logging for all API traffic, acting as a single controlled entry point.
In the context of DevSecOps, what does 'shift left' security mean?
Answer: Integrating security practices early in the development lifecycle rather than only at the end
Shifting left means introducing security testing, code analysis, and threat modeling early in development rather than waiting until the deployment or production phase.