CCSP · Question #26
The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common threats to organizations participating in cloud computing. According to the CSA, what is one reason the threat of…
The correct answer is A. Most of the cloud customer's interaction with resources will be performed through APIs. Insecure interfaces and APIs are a significant cloud threat because APIs serve as the primary means for customers to interact with and manage their cloud resources.
Question
The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common threats to organizations participating in cloud computing. According to the CSA, what is one reason the threat of insecure interfaces and APIs is so prevalent in cloud computing?
Options
- AMost of the cloud customer's interaction with resources will be performed through APIs.
- BAPIs are inherently insecure.
- CAttackers have already published vulnerabilities for all known APIs.
- DAPIs are known carcinogens.
How the community answered
(36 responses)- A86% (31)
- B3% (1)
- C8% (3)
- D3% (1)
Why each option
Insecure interfaces and APIs are a significant cloud threat because APIs serve as the primary means for customers to interact with and manage their cloud resources.
According to the CSA, insecure interfaces and APIs are a prevalent threat in cloud computing because customers largely rely on these interfaces to manage and interact with their cloud services and data. If these APIs are poorly designed, implemented, or secured, they present a significant attack surface that can be exploited by malicious actors, leading to data breaches or system compromise.
APIs are not inherently insecure; their security depends on their design, implementation, and how they are used and protected.
While vulnerabilities are discovered and published for specific APIs, it is false to claim that attackers have published vulnerabilities for *all* known APIs.
"APIs are known carcinogens" is a nonsensical statement and completely unrelated to IT security or cloud computing.
Concept tested: CSA Notorious Nine: Insecure Interfaces and APIs
Source: https://cloudsecurityalliance.org/research/artifacts/the-notorious-nine-cloud-computing-threats-v1-0/
Topics
Community Discussion
No community discussion yet for this question.