CCSP - Cloud Application Security - Section 4.1

Advocate training and awareness for application security.

Cloud development basics, common implementation pitfalls, and the common cloud vulnerabilities that developer security training and awareness is meant to prevent.

secure development trainingOWASP Top 10common cloud vulnerabilitiescloud development pitfalls

Practice question for this objective

Free sampleCloud Application Securityeasy

A team lead wants developer training to focus on the most common categories of web application security risk. Which resource is specifically designed to catalogue those widespread risks for awareness and training?

  • AThe OWASP Top 10, a consensus list of the most critical web application security risks. Correct
  • BThe shared responsibility model, which allocates security duties between the cloud provider and the customer.
  • CA service level agreement, which defines the availability and performance commitments of a cloud service.
  • DA recovery time objective, which sets the maximum tolerable duration to restore a service after disruption.
The OWASP Top 10 is the standard awareness reference for the most common web application security risks used in developer training. The OWASP Top 10 exists precisely to raise awareness of the categories of web application weakness that appear most often and cause the most harm, such as injection and broken access control. It gives training programmes a shared, prioritised vocabulary, which is why it is the resource pointed to for application security awareness rather than contractual or continuity artefacts.

Why A is correct: Correct. The OWASP Top 10 is a widely used awareness document that ranks the most common and impactful web application security risks.

Why B is wrong: Tempting because it is central to cloud security, but it divides operational responsibility rather than cataloguing common application vulnerabilities.

Why C is wrong: Tempting because it governs the provider relationship, but an SLA sets service commitments and does not list web application risks.

Why D is wrong: Tempting because it is a familiar security metric, but an RTO is a continuity target and has nothing to do with cataloguing application risks.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Cloud Application Security objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.