ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During an internal audit of a cloud-hosted retail application, the security team must confirm that the new API gateway continues to correctly enforce authentication and remains available when subjected to the forecast holiday traffic spike of 5,000 requests per second. Which type of testing incorporated into the CI/CD pipeline would best address both requirements with a single test run?
Schedule a black-box penetration test of the production gateway during a normal off-peak maintenance window.
Run dynamic application security testing concurrently with scripted load and stress tests against the API gateway in the staging environment.
Conduct a manual peer code review focused on authentication routines in the gateway source repository.
Perform a static code analysis of the gateway microservice during the build stage.
Executing dynamic application security tests (DAST) while the system is under an automated load allows the team to validate that security controls (a functional requirement) still behave correctly and, at the same time, observe the gateway's responsiveness and stability under peak traffic (a non-functional requirement). Static analysis and SCA occur before runtime and cannot measure availability under load. Manual code reviews likewise miss performance impacts. A penetration test performed without stressing the system evaluates exploitability but not its ability to stay available at scale.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Dynamic Application Security Testing (DAST)?
Open an interactive chat with Bash
How do load and stress tests help ensure application availability?
Open an interactive chat with Bash
Why is combining DAST with load testing better than relying solely on static analysis?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .