Question 26

Which secure software design principle states that it is always safer to require agreement of more than one entity to make a decision?
  • Question 27

    After being notified of a vulnerability in the company's online payment system, the Product Security Incident Response Team (PSIRT) was unable to recreate the vulnerability in a testing lab.
    What is the response team's next step?
  • Question 28

    The security team has received notice of an insecure direct object reference vulnerability in a third-party component library that could result in remote code execution. The component library was replaced and is no longer being used within the application.
    How should the organization remediate this vulnerability?
  • Question 29

    Which secure coding practice uses role-based authentication where department-specific credentials will authorize department-specific functionality?
  • Question 30

    What is the privacy impact rating of an application that stores personally identifiable information, monitors users with ongoing transfers of anonymous data, and changes settings without notifying the user?