Question 226

Application sometimes store configuration as constants in the code, which is a violation of strict separation of configuration from code. Where should application configuration be stored?
  • Question 227

    Which type of file is created from issued intermediate, root, and primary certificates for SSL installation on a server?
  • Question 228

    Which two techniques protect against injection attacks? (Choose two.)
  • Question 229

    Drag and drop the descriptions from the left onto the related OAuth-defined roles on the right.

    Question 230

    Which two methods are API security best practices? (Choose two.)