ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During a post-deployment penetration test of a newly launched SaaS application hosted in a public IaaS environment, testers exploited a feature that lets users supply external image URLs. By abusing the feature, they performed server-side request forgery (SSRF) and retrieved temporary access tokens from the instance metadata service at 169.254.169.254. You are creating a developer awareness session based on the test findings. Which single guideline would most directly prevent a recurrence of this vulnerability in future releases?
Run static code analysis before each release to detect any hard-coded credentials in the source repository.
Enforce output encoding on every response to the client to block reflected scripting attacks.
Implement strict allow-lists for outbound requests in the image-fetch function and apply network egress filtering to block access to internal metadata endpoints.
Require the use of parameterized SQL statements for all database queries.
SSRF occurs when an attacker tricks a server-side component into making unintended requests. In cloud environments, a common target is the instance metadata endpoint, which can expose sensitive credentials. The most effective developer guidance is to ensure the application never makes arbitrary outbound requests supplied by users. Enforcing strict allow lists (or deny lists) for destination URLs and applying egress controls at the network layer prevents untrusted input from being used to reach protected internal resources such as the metadata service. While parameterized SQL defends against SQL injection, output encoding mitigates XSS, and scanning for hard-coded secrets addresses an entirely different issue; none of those measures specifically stop SSRF attacks that pivot to cloud metadata.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Server-Side Request Forgery (SSRF)?
Open an interactive chat with Bash
What is the instance metadata service and why is it a common target in SSRF attacks?
Open an interactive chat with Bash
How do network egress filters help prevent SSRF attacks?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .