CISSP Software Development Security Practice Question
A security engineer is hardening a web server before deploying a new application. Which TWO of the following are examples of security misconfiguration vulnerabilities that should be addressed?
⚠ Common exam trap
The CISSP exam often tests the distinction between 'security misconfiguration' and other vulnerability types (e.g., using outdated libraries is a 'using components with known vulnerabilities' issue, not a misconfiguration), so candidates mistakenly classify all common weaknesses as misconfigurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Default administrator credentials remain unchanged
Option B is correct because leaving default administrator credentials unchanged is a classic security misconfiguration: the system is deployed with vendor-supplied accounts (e.g., admin/admin) that attackers can trivially guess, and hardening requires changing or disabling them. Option C is correct because verbose error messages that expose stack traces, framework versions, or file paths are a misconfiguration of error handling and debug settings (e.g., ASP.NET customErrors=Off or Django DEBUG=True), leaking information useful for further attacks. Option A does not belong because using an outdated JavaScript library with known CVEs is a vulnerable component/software supply chain issue, not a configuration error. Option D does not belong because missing CSRF tokens is a code-level application flaw (broken access/request forgery protection), not a misconfiguration. Option E does not belong because a weak password policy is an authentication/identity policy weakness rather than a system or server misconfiguration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use of an outdated version of a JavaScript library with known vulnerabilities
Why it's wrong here
This scenario represents a vulnerability stemming from the use of insecure or outdated third-party components, a common issue in software supply chains. While it introduces a significant security risk, it is fundamentally distinct from a misconfiguration, which involves incorrect or suboptimal settings within the server's own configuration files or deployed application settings. This is a software composition analysis problem, not a configuration management one.
- ✓
Default administrator credentials remain unchanged
Why this is correct
Leaving default administrator credentials unchanged is a quintessential example of a security misconfiguration. These credentials are often publicly known or easily guessable, providing attackers with a straightforward entry point if not immediately altered post-installation. Proper hardening requires modifying all default passwords and usernames to unique, strong values, ensuring the system's initial setup doesn't become its weakest link.
- ✓
Verbose error messages reveal stack traces to users
Why this is correct
Displaying verbose error messages, especially those containing stack traces, is a critical security misconfiguration. This exposes sensitive internal system details, such as file paths, database schema information, or application logic, which attackers can leverage for further exploitation. Secure configurations dictate that error messages presented to end-users should be generic and non-informative, logging detailed errors internally for administrative review only.
- ✗
Lack of CSRF tokens in forms
Why it's wrong here
The absence of Cross-Site Request Forgery (CSRF) tokens in web forms signifies a missing security control within the application's design or development, rather than a server misconfiguration. CSRF protection is an application-level security mechanism implemented in code to prevent unauthorized commands from being transmitted from a user's browser. While a serious vulnerability, it's not about incorrect server settings but a fundamental flaw in the application's security architecture.
- ✗
Weak password policy allowing short passwords
Why it's wrong here
A weak password policy that permits short or easily guessable passwords falls under the category of "Broken Authentication" or "Insecure Authentication Mechanisms." While related to security settings, it primarily concerns the robustness of the authentication system itself and the rules governing user credentials, rather than an incorrect server or application configuration parameter. This issue directly impacts the integrity and strength of user identity verification.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.