ISC2 Certified Cloud Security Professional (CCSP) Practice Question
While troubleshooting an API hosted on IaaS virtual machines, you notice repeated calls to 169.254.169.254 right after each external request is processed. The developer explains that the code pulls temporary cloud credentials from the instance metadata service on every transaction. From a secure cloud development perspective, which change should you recommend first to reduce the risk of Server-Side Request Forgery (SSRF) attacks against the metadata endpoint?
Remove outbound egress filtering to ensure the metadata service remains reachable even under heavy load.
Store static access keys in environment variables so the code no longer contacts the metadata IP address.
Configure the application to use the cloud provider's hardened metadata service flow that requires a session token or header (e.g., IMDSv2) before credentials are returned.
Implement mutual TLS between microservices and stop using the metadata service entirely.
Modern cloud platforms provide hardened versions of their instance metadata services that require the workload to present a short-lived session token or custom request header before any credentials are returned (for example, AWS IMDSv2 or Azure's scheduled-key approach). Switching the application to this protected flow removes unauthenticated HTTP access to the endpoint, making common SSRF techniques-where an attacker tricks the application into querying the metadata IP-far harder to exploit. Embedding long-lived keys, disabling egress controls, or introducing mutual TLS between microservices do not address the core problem of unauthenticated, on-demand metadata calls and may even weaken the overall security posture.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Server-Side Request Forgery (SSRF)?
Open an interactive chat with Bash
What is IMDSv2, and how does it improve security?
Open an interactive chat with Bash
Why is using static access keys considered insecure in cloud environments?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .