ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization is decomposing a monolithic application into containerized microservices hosted on a managed Kubernetes service. Security policy mandates that external clients must never talk directly to individual microservices. The chosen control must also provide centralized authentication, rate limiting, and protocol translation (for example, HTTP/JSON to gRPC) while exposing a single public endpoint. Which supplemental security component best satisfies these requirements?

  • API gateway in front of the microservices

  • Service-mesh sidecar proxies on each microservice pod

  • Database activity monitoring (DAM) appliance

  • Web application firewall (WAF) protecting the cluster ingress

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot