Q: 11
What is a best practice of secure coding?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
The software security team is using an automation tool that generates random data to input into
every field in the new product and track results.
Which security testing technique is being used?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
The Chief Information Security Officer (CISO) has recommended contracting with external experts to
perform annual reviews of the enterprise's software products, including penetration testing.
Which post-release deliverable is being described?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
During fuzz testing of the new product, an exception was thrown on the order entry view, which
caused a full stack dump to be displayed in the browser window that included function names from
the source code.
How should existing security controls be adjusted to prevent this in the future?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
Security testers have completed testing and are documenting the results of vulnerability scans and
penetration analysis They are also creating documentation lo share with the organization's largest
customers.
Which deliverable is being prepared?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
A product team, consisting of a Scrum Master, a Business Analyst, two Developers, and a Quality
Assurance Tester, are on a video call with the Product Owner. The team is reviewing a list of work
items to determine how many they feel can be added to their backlog and completed within the next
two-week iteration.
Which Scrum ceremony is the team participating in?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
Which secure coding best practice says to only use tested and approved components and use task-
specific, built-in APIs to conduct operating system functions?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
The product development team is preparing for the production deployment of recent feature
enhancements. One morning, they noticed the amount of test data grew exponentially overnight.
Most fields were filled with random characters, but some structured query language was discovered.
Which type of security development lifecycle (SDL) tool was likely being used?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
Which secure coding best practice says to assume all incoming data should be considered untrusted
and should be validated to ensure the system only accepts valid data?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
Which secure coding best practice says to use well-vetted algorithms to ensure that the application
uses random identifiers, that identifiers are appropriately restricted to the application, and that user
processes are fully terminated on logout?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 11 of 20 · Page 2 / 2