ISC2 Certified Cloud Security Professional (CCSP) Practice Question

During a post-mortem after a production incident, your SaaS team discovers that the cloud-hosted web front-end becomes unresponsive whenever traffic suddenly rises from 200 to 2 000 concurrent sessions. The current CI/CD pipeline already runs unit tests, service-level integration tests, and static application security scanning. To detect this kind of problem earlier while keeping the process fully automated, which additional QA activity should you add to the pipeline?

  • Run software composition analysis (SCA) to detect vulnerable third-party libraries in the build artifacts.

  • Insert an interactive application security testing (IAST) stage to monitor the running code for vulnerabilities.

  • Schedule a manual exploratory testing session by the QA team at the end of each sprint.

  • Add an automated load or stress performance test that drives high-volume concurrent requests against a staging environment.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot