Question 26
Automated security testing was performed by attempting to log in to the new product with a known username using a collection of passwords. Access was granted after a few hundred attempts.
How should existing security controls be adjusted to prevent this in the future?
How should existing security controls be adjusted to prevent this in the future?
Question 27
Which DKEAD category has a risk rating based on the threat exploit's potential level of harm?
Question 28
Which type of threat exists when an attacker can intercept and manipulate form data after the user clicks the save button but before the request is posted to the API?
Question 29
The software security group is conducting a maturity assessment using the Building Security in Maturity Model (BSIMM). They are currently focused on reviewing attack models created during recently completed initiatives.
Which BSIMM domain is being assessed?
Which BSIMM domain is being assessed?
Question 30
In which step of the PASTA threat modeling methodology will the team capture infrastructure, application, and software dependencies?
