Question 1
While performing functional testing of the ordering feature in the new product, a tester noticed that the order object was transmitted to the POST endpoint of the API as a human-readable JSON object.
How should existing security controls be adjusted to prevent this in the future?
How should existing security controls be adjusted to prevent this in the future?
Question 2
Company leadership has discovered an untapped revenue stream within its customer base and wants to meet with IT to share its vision for the future and determine whether to move forward.
Which phase of the software development lifecycle (SDLC) is being described?
Which phase of the software development lifecycle (SDLC) is being described?
Question 3
Which threat modeling approach concentrates on things the organization wants to protect?
Question 4
The security team is identifying technical resources that will be needed to perform the final product security review.
Which step of the final product security review process are they in?
Which step of the final product security review process are they in?
Question 5
What is one of the tour core values of the agile manifesto?
