Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
A cloud application exposes several APIs that are consumed by both internal microservices and external partner applications. To protect these APIs from common web-based attacks, enforce rate limiting, and centralize authentication/authorization, which security component should be implemented?
- AAPI Gateway.
- BIdentity Provider (IdP).
- CContent Delivery Network (CDN).
- DWeb Application Firewall (WAF).
Show answer & explanationAnswer & explanation
Correct answer: A. API Gateway.
An API Gateway serves as the single entry point for all API requests. It can enforce security policies (like authentication, authorization, and rate limiting), provide traffic management, and protect backend services. While a WAF can protect against web attacks, an API Gateway offers more comprehensive API-specific security and management features.
Why the other options are wrong
- B. An IdP manages user identities and issues tokens for authentication but doesn't sit in front of the APIs to enforce policies or route traffic.
- C. A CDN primarily caches content for faster delivery and offers some DDoS protection, but it's not designed for API security management like authentication or rate limiting.
- D. A WAF protects against general web attacks but doesn't typically handle API-specific authentication, authorization, or rate limiting at the same comprehensive level as an API Gateway.
API Gateway
An API Gateway acts as a single entry point for all API calls, handling routing, composition, and security concerns such as authentication, authorization, rate limiting, and caching.
- Centralizes API security policies.
- Protects backend services.
- Provides traffic management and monitoring.
Memory trick: API Gateway is the main GATeway for all API calls.