Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
A cloud application processes user-uploaded files, which are then stored in object storage. A potential vulnerability exists if malicious files are uploaded and then served directly to other users without proper validation. Which security best practice should be implemented to mitigate the risk of content-related attacks (e.g., XSS via uploaded HTML, executable code) in this scenario?
- ARestricting access to the object storage bucket to authorized administrators only.
- BScanning uploaded files for malware and validating file types and content.
- CImplementing server-side encryption for all uploaded files.
- DUsing a Content Delivery Network (CDN) to cache and serve the files.
Show answer & explanationAnswer & explanation
Correct answer: B. Scanning uploaded files for malware and validating file types and content.
Scanning for malware and validating file types and content ensures that malicious files are not stored or served, directly mitigating risks like XSS or execution of unauthorized code from user uploads.
Why the other options are wrong
- A. Restricting object storage access to administrators is a good practice for management, but it doesn't prevent authorized users from uploading malicious content that could impact other users.
- C. Server-side encryption protects data confidentiality at rest but does not prevent malicious content from being uploaded or executed.
- D. A CDN improves performance and availability but does not inherently provide security validation for the content being served.
Secure File Uploads
Security best practices for handling user-uploaded files to prevent malicious content from being stored, processed, or served to other users.
- Validate file type and content.
- Scan for malware.
- Store files outside the web root.
Memory trick: Uploaded Files: 'Scan and Sanitize' before they spread.