ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your company is integrating with a cloud provider's RESTful management API to automate user provisioning. The integration uses OAuth tokens sent over TLS. Penetration testers demonstrate that by modifying the URI parameters they can enumerate and read records belonging to other tenants because the API fails to perform proper authorization checks after authentication. Which cloud-specific threat category does this vulnerability BEST exemplify?
Insecure or insufficiently protected application programming interfaces
Malicious insider planting cryptomining malware in shared workloads
Supply-chain compromise of the provider's underlying hardware firmware
Hypervisor breakout that allows a guest VM to access the host
The situation describes an interface that is exposed to customers and partners over the Internet. Although the connection is encrypted and the caller is authenticated, the API itself does not verify whether the requester is authorized to access each specific resource. The Cloud Security Alliance lists insecure interfaces and APIs as a primary threat because a single flaw in authorization, input validation, or rate limiting can lead to data leakage, privilege escalation, or service disruption across multiple tenants. Hypervisor breakouts, supply-chain firmware compromises, and insider cryptomining are valid cloud threats, but none are related to weak authorization logic in customer-facing APIs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is OAuth and how does it work in API authentication?
Open an interactive chat with Bash
What are insecure or insufficiently protected APIs in cloud security?
Open an interactive chat with Bash
What is the difference between authentication and authorization in API security?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .