View Mode
Q: 16
SIMULATION [Identity and Access Management (IAM)] A product development team has submitted code snippets for review prior to release. INSTRUCTIONS Analyze the code snippets, and then select one vulnerability, and one fix for each code snippet. Code Snippet 1 Security X CASP+ CAS-005 question Code Snippet 2 Security X CASP+ CAS-005 question Vulnerability 1: SQL injection Cross-site request forgery Server-side request forgery Indirect object reference Cross-site scripting Fix 1: Perform input sanitization of the userid field. Perform output encoding of queryResponse, Ensure usex:ia belongs to logged-in user. Inspect URLS and disallow arbitrary requests. Implementanti-forgery tokens. Vulnerability 2 1) Denial of service 2) Command injection 3) SQL injection 4) Authorization bypass 5) Credentials passed via GET Fix 2 A) Implement prepared statements and bind variables. B) Remove the serve_forever instruction. C) Prevent the "authenticated" value from being overridden by a GET parameter. D) HTTP POST should be used for sensitive parameters. E) Perform input sanitization of the userid field.
Your Answer
Question 16 of 30

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top

FLASH OFFER

Days
Hours
Minutes
Seconds

avail 10% DISCOUNT on YOUR PURCHASE