Certified Cloud Security Professional (CCSP)Cloud Application SecurityHard

A company is developing a cloud-native mobile application that interacts with backend APIs. The security team is concerned about unauthorized access to the APIs, especially from malicious applications impersonating legitimate users. Which of the following security mechanisms is most effective for ensuring that API requests originate from the legitimate mobile application and not from unauthorized clients?

  1. AImplementing Mobile App Attestation or client-side certificate pinning.
  2. BUsing API keys embedded in the mobile application for authentication.
  3. CImplementing a strong Web Application Firewall (WAF) in front of the APIs.
  4. DRelying solely on OAuth 2.0 authorization code flow with PKCE.
Show answer & explanation

Correct answer: A. Implementing Mobile App Attestation or client-side certificate pinning.

Mobile App Attestation (e.g., Google Play Integrity API, Apple App Attest) or client-side certificate pinning are designed to verify the integrity and authenticity of the mobile application itself. This helps ensure that API requests are indeed originating from a legitimate, untampered version of the app, protecting against impersonation by malicious clients.

Why the other options are wrong

  • B. API keys embedded in mobile apps can be easily extracted and reused by malicious clients, offering weak protection against impersonation.
  • C. A WAF protects against general web attacks but cannot verify the authenticity or integrity of the specific mobile application client making the request.
  • D. OAuth 2.0 with PKCE protects the authorization code flow from interception but does not inherently verify the integrity or authenticity of the client application itself, only the user's authorization.

Mobile App Attestation / Client-Side Certificate Pinning

Techniques used to verify that API requests originate from a legitimate, untampered version of a mobile application, preventing impersonation by malicious clients.

  • Verifies app integrity and authenticity.
  • Protects against API abuse from fake clients.
  • Hardens client-side security.

Memory trick: Attestation confirms the App is real.

More Cloud Application Security questions