ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During a threat modeling session, you are asked to choose an appropriate target verification level from the OWASP Application Security Verification Standard (ASVS) for a newly written microservice. The microservice is publicly reachable via a REST API, accepts credit-card account data and personal identifiers, and stores them in an encrypted cloud database. What is the minimum ASVS verification level the development team should commit to achieving?
Level 1 - Basic, because the serverless environment inherits sufficient security controls from the provider.
Level 1 - Basic, because it covers all internet-facing applications with minimal risk.
Level 2 - Standard, because it is the baseline for internet-exposed applications that handle sensitive data such as PII and payment information.
Level 3 - Advanced, because any code running in the cloud must meet the highest ASVS requirements.
OWASP ASVS defines three assurance levels. Level 1 is intended for low-risk or internal applications and provides a basic set of controls. Level 2 is the required baseline for any application that processes or stores sensitive data such as personally identifiable information (PII) or payment data and is exposed to the internet. Level 3 is reserved for critical systems that could pose a risk to life or national security. Because the microservice is internet-facing and handles both PII and payment information, Level 2 is the minimum acceptable target. Options suggesting Level 1 ignore the sensitivity of the data, and mandating Level 3 exceeds the minimum needed for this use case.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is OWASP ASVS and why is it important?
Open an interactive chat with Bash
What distinguishes ASVS Level 1, Level 2, and Level 3?
Open an interactive chat with Bash
How does threat modeling help determine the correct ASVS level?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .