ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A company is migrating its customer-records service to a public cloud and will expose it as a RESTful API for mobile apps and external partners. The architect must ensure that, if an attacker steals a bearer access token, the token cannot be reused from a different device or network. The solution must keep the API stateless so that horizontal scaling behind a load balancer is unaffected. Which security control BEST meets these requirements?

  • Configure a web application firewall rule to reject any request missing a valid user-agent header.

  • Enforce mutual TLS at the API gateway and bind each access token to the client's X.509 certificate.

  • Restrict the API endpoint to known partner IP address ranges with a cloud network security group.

  • Issue short-lived JSON Web Tokens (JWT) via OAuth 2.0 and require clients to refresh them frequently.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot