← All CCSP Flashcard Decks

Cloud Application Security Flashcards

6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Cloud Application Security flashcards as text
  1. Which OWASP Top 10 vulnerability involves attackers manipulating SQL queries by injecting malicious input?

    Answer: SQL Injection

    SQL injection occurs when user-supplied input is incorporated into a SQL query without proper sanitization, allowing attackers to manipulate the database.

  2. What is the primary purpose of a Web Application Firewall (WAF) in cloud application security?

    Answer: To filter and monitor HTTP traffic to protect web applications from common exploits

    A WAF inspects HTTP/HTTPS requests and responses, blocking attacks such as SQL injection, XSS, and CSRF before they reach the application.

  3. In secure software development for cloud applications, what does SAST (Static Application Security Testing) analyze?

    Answer: Source code or compiled binaries without executing the program

    SAST tools analyze source code, bytecode, or binaries statically to identify security vulnerabilities early in the development lifecycle before the code runs.

  4. What is OAuth 2.0 primarily used for in cloud applications?

    Answer: Delegated authorization, allowing applications to access resources on behalf of users without sharing credentials

    OAuth 2.0 is an authorization framework that enables a third-party application to obtain limited access to a service on behalf of a user without exposing their password.

  5. Which secure development practice involves reviewing code written by another developer to identify security flaws before deployment?

    Answer: Peer code review / security code review

    Security-focused code review uses a second developer (or automated tool) to scrutinize code for vulnerabilities before it is merged or deployed.

  6. What does the term 'defense in depth' mean when applied to cloud application security?

    Answer: Applying multiple overlapping layers of security controls so that no single failure compromises the whole system

    Defense in depth stacks multiple independent security controls (WAF, authentication, encryption, monitoring) so that an attacker must bypass every layer to succeed.