Question 36

Which privacy impact statement requirement type defines processes to keep personal information updated and accurate?
  • Question 37

    The software security group is conducting a maturity assessment using the Open Web Application Security Project Software Assurance Maturity Model (OWASP SAMM). They are currently focused on reviewing design artifacts to ensure they comply with organizational security standards.
    Which OpenSAMM business function is being assessed?
  • Question 38

    A potential threat was discovered during vulnerability testing when an environment configuration file was found that contained the database username and password stored in plain text.
    How should existing security controls be adjusted to prevent this in the future?
  • Question 39

    What are the three primary goals of the secure software development process?
  • Question 40

    Using a web-based common vulnerability scoring system (CVSS) calculator, a security response team member performed an assessment on a reported vulnerability in the user authentication component of the company's now product. The base score of the vulnerability was 8.3 and changed to 9.4 after adjusting temporal and environmental metrics.
    Which rating would CVSS assign this vulnerability?