Question 6
During fuzz testing of the new product, an exception was thrown on the order entry view, which caused a full stack dump to be displayed in the browser window that included function names from the source code.
How should existing security controls be adjusted to prevent this in the future?
How should existing security controls be adjusted to prevent this in the future?
Question 7
Which threat modeling step assigns a score to discovered threats?
Question 8
Which question reflects the security change management component of the change management process?
Question 9
Which secure coding practice involves clearing all local storage as soon as a user logs of for the night and will automatically log a user out after an hour of inactivity?
Question 10
Recent vulnerability scans discovered that the organization's production web servers were responding to ping requests with server type, version, and operating system, which hackers could leverage to plan attacks.
How should the organization remediate this vulnerability?
How should the organization remediate this vulnerability?
