Question 416

Which of the following threat types involves an application that does not validate authorization for portions of itself beyond when the user first enters it?
  • Question 417

    You are the security manager for a software development firm. Your company is interested in using a managed cloud service provider for hosting its testing environment. Previous releases have shipped with major flaws that were not detected in the testing phase; leadership wants to avoid repeating that problem.
    What tool/technique/technology might you suggest to aid in identifying
    programming errors?
  • Question 418

    Which of the following is NOT part of a retention policy?
  • Question 419

    Which of the following is NOT a major regulatory framework?
  • Question 420

    What is the best approach for dealing with services or utilities that are installed on a system but not needed to perform their desired function?