CAIQ v4 Control APP-09 Extractive Review Standard

How to answer 'How are public API endpoints protected against abuse and DDoS attacks?' on a CAIQ

Reviewer Guidance & Pitfalls

Describe API authentication (OAuth 2.0 / Bearer tokens), strict IP and tenant rate limiting, payload size validation, and Cloudflare/WAF edge DDoS mitigation.

Example Answer Passing Enterprise Audit

Compliant Response Template
APIs require cryptographically signed Bearer tokens, enforce per-tenant and per-IP rate limiting, and sit behind Cloudflare edge DDoS mitigation with automated bot protection (SOC 2, CC6.6).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.