CISSP Software Development Security Practice Question
A security team is performing a risk assessment on a legacy application that uses insecure deserialization. Which TWO of the following are recommended approaches to mitigate the risk of insecure deserialization?
⚠ Common exam trap
Many candidates confuse encryption with integrity protection, thinking that encrypting serialized data prevents tampering, but encryption alone does not provide authentication or integrity — an attacker can still modify ciphertext (bit-flipping attacks) unless combined with a MAC or digital signature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing integrity checks (e.g., digital signatures) on serialized objects
Option A is correct because applying integrity checks such as digital signatures or HMACs to serialized objects lets the receiving application verify that the data was not tampered with before deserialization, preventing attackers from injecting malicious serialized payloads. Option C is correct because an allow list (whitelist) restricts deserialization to only explicitly permitted, trusted classes, blocking the instantiation of dangerous gadget classes that enable remote code execution. Option B is not recommended as a primary mitigation because encryption provides confidentiality but does not prevent an attacker who can supply or replay ciphertext from triggering malicious deserialization, and it does not validate object integrity or class types. Option D is not appropriate because generic exception handling only masks errors and does not stop malicious objects from being deserialized and executed. Option E is not a mitigation because logging deserialization attempts is a detective control that records activity but does not prevent exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementing integrity checks (e.g., digital signatures) on serialized objects
Why this is correct
A digital signature, applied by the sender, creates a cryptographic hash of the serialized object and encrypts it with the sender's private key. Upon deserialization, the receiver can verify this signature using the sender's public key and the sender's public key certificate. This process cryptographically guarantees that the serialized data has not been altered in transit, preventing an attacker from injecting malicious code or modifying object properties before deserialization occurs.
- ✗
Encrypting the serialized data
Why it's wrong here
Encryption primarily ensures confidentiality, meaning unauthorized parties cannot read the serialized data, but it does not inherently provide integrity. An attacker could still modify the encrypted data in a way that, when decrypted and deserialized, could lead to a malicious object or code execution. Without integrity checks, an attacker could substitute a valid encrypted payload with a different, equally valid (but malicious) encrypted payload if they understand the structure or can replay known attacks, without breaking the encryption itself.
- ✓
Using allow lists for classes that can be deserialized
Why this is correct
An allow list (or whitelist) explicitly defines a set of trusted classes that the application is permitted to deserialize. Any attempt to deserialize an object belonging to a class not on this predefined list is immediately rejected, regardless of the object's content. This mechanism effectively prevents attackers from introducing and instantiating arbitrary or malicious classes, which is a common vector for remote code execution vulnerabilities in deserialization attacks.
- ✗
Using generic exception handling to catch errors
Why it's wrong here
Generic exception handling, such as a broad `try-catch` block, is designed to gracefully manage runtime errors and prevent application crashes, not to prevent security vulnerabilities. While it can catch exceptions that occur during a deserialization attempt, it does not prevent the underlying deserialization vulnerability from being exploited. The malicious code or object could still be processed before the exception is triggered, or the exception might only occur *after* the harmful action has already taken place, making it a reactive rather than a preventative measure.
- ✗
Logging all deserialization attempts
Why it's wrong here
Logging deserialization attempts creates an audit trail, which is valuable for forensic analysis, incident response, and identifying potential attack patterns after an event has occurred. However, logging is a detective control; it does not actively prevent an attacker from successfully exploiting a deserialization vulnerability in real-time. The malicious payload would still be processed and potentially executed before the log entry is even written, meaning the system is already compromised.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Detective control
A detective control is a security measure that identifies and reports unwanted or suspicious activity after it has already occurred.
Key term
Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential threats to an organization's assets to determine the likelihood and impact of those threats, and to decide on appropriate treatment measures.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.