Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
A cloud application processes user-uploaded images. Before storing these images in object storage, the application must scan them for malware and ensure they do not contain sensitive metadata (EXIF data) that could expose user privacy. Which of the following security best practices should be implemented to address these requirements?
- APerform server-side validation and sanitization of uploaded files.
- BStore images in an encrypted database instead of object storage.
- CImplement a Content Delivery Network (CDN) with WAF capabilities.
- DUtilize client-side JavaScript for file type and size validation.
Show answer & explanationAnswer & explanation
Correct answer: A. Perform server-side validation and sanitization of uploaded files.
Server-side validation and sanitization are critical for processing uploaded files. This includes scanning for malware, stripping sensitive metadata (like EXIF data), and validating file types and contents. Client-side checks are easily bypassed and insufficient for security.
Why the other options are wrong
- B. Storing images in a database is generally not efficient or cost-effective compared to object storage for large binary files and doesn't inherently provide malware scanning or metadata stripping capabilities.
- C. A CDN with WAF primarily protects against web attacks and distributed denial-of-service, not specifically for scanning uploaded files for malware or stripping metadata.
- D. Client-side validation can improve user experience but is easily bypassed by malicious actors and cannot be relied upon for security-critical tasks like malware scanning or metadata stripping.
Secure File Uploads (Server-Side Processing)
Implementing robust server-side processing for uploaded files, including validation of type, size, and content, malware scanning, and sanitization (e.g., metadata stripping).
- Client-side checks are insufficient.
- Prevents malware injection and privacy leaks.
- Crucial for data integrity and security.
Memory trick: Server-side checks clean files, keeping everything safe.