Courseiva

CCNA Software Development Security Questions

42 questions · Software Development Security · All types, answers revealed

1
MCQmedium

Which type of testing analyzes source code for security vulnerabilities without executing the program?

A.Static Application Security Testing (SAST)
B.Interactive Application Security Testing (IAST)
C.Penetration testing
D.Dynamic Application Security Testing (DAST)
AnswerA

Static Application Security Testing (SAST) tools analyze an application's source code, bytecode, or binary code without actually executing the program. This "white-box" testing approach identifies security vulnerabilities such as SQL injection, cross-site scripting (XSS), and buffer overflows by examining code patterns, data flow, and control flow paths that could lead to exploits. It is typically performed early in the Software Development Life Cycle (SDLC), providing developers with immediate feedback on potential flaws before deployment.

Why this answer

Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code for security vulnerabilities without executing the program. It operates by scanning the codebase for known patterns, such as SQL injection or buffer overflow, using techniques like data flow analysis and taint tracking. This white-box approach identifies issues early in the Software Development Life Cycle (SDLC), making it the correct answer for testing that does not require runtime execution.

Exam trap

The trap here is that candidates confuse SAST with DAST because both are automated security testing tools, but SAST is static (no execution) and DAST is dynamic (requires execution), and the question explicitly states 'without executing the program' to eliminate DAST.

How to eliminate wrong answers

Option B (Interactive Application Security Testing, IAST) is wrong because IAST requires the application to be running and instruments the code during execution to detect vulnerabilities, often combining elements of SAST and DAST. Option C (Penetration testing) is wrong because it is a manual or automated black-box/gray-box test that actively exploits vulnerabilities in a running system, not analyzing source code statically. Option D (Dynamic Application Security Testing, DAST) is wrong because it tests the application from the outside while it is executing, typically by sending HTTP requests and analyzing responses, without access to the source code.

2
MCQhard

A security engineer is evaluating a new third-party software component for use in a critical application. Which document is most important to review to understand the component's supply chain security?

A.End User License Agreement (EULA)
B.Service Level Agreement (SLA)
C.Data Processing Agreement (DPA)
D.Software Bill of Materials (SBOM)
AnswerD

A Software Bill of Materials (SBOM) is a formal, machine-readable inventory of all the software components and dependencies used in a particular application, including open-source and commercial libraries. It provides a comprehensive list of ingredients, their versions, and often their licenses, offering crucial transparency into the software's supply chain. For a security engineer, an SBOM is invaluable for identifying potential vulnerabilities, tracking known exploits (like Log4Shell), and managing risks associated with third-party components, making it the ideal tool for evaluating new software.

Why this answer

The Software Bill of Materials (SBOM) is the most important document because it provides a complete inventory of all components, libraries, and dependencies in the software, including their versions and supply chain relationships. This transparency is essential for identifying vulnerabilities, assessing third-party risk, and meeting supply chain security requirements. EULA, SLA, and DPA address legal, service, and data privacy terms, not supply chain security.

Exam trap

CISSP often tests the confusion between legal/privacy documents (EULA, SLA, DPA) and technical supply chain artifacts (SBOM); candidates must recognize that only the SBOM provides component-level visibility.

How to eliminate wrong answers

Option A is wrong because the EULA defines licensing terms and usage rights, not the component inventory or supply chain risk. Option B is wrong because the SLA defines service performance and support commitments, not the software's internal composition. Option C is wrong because the DPA governs how personal data is processed and protected, which is a privacy concern, not supply chain security.

3
MCQhard

A development team is using a third-party library that is known to have a critical vulnerability. The team decides to continue using the library because it is widely used and the vulnerability has not been exploited. Which security risk is the team ignoring?

A.Insecure deserialization
B.Insufficient logging and monitoring
C.Using components with known vulnerabilities
D.Security misconfiguration
AnswerC

This option precisely describes the scenario where a development team incorporates a third-party library that contains publicly disclosed security flaws. Such components, often found in open-source libraries or commercial software, introduce significant risk because attackers can exploit these known weaknesses. Proactively identifying and remediating these vulnerabilities, typically through patching or replacement, is critical for maintaining application security posture.

Why this answer

The team is ignoring the risk of using components with known vulnerabilities, which is explicitly listed in the OWASP Top 10 (A06:2021). Even if a vulnerability has not been exploited yet, continuing to use a library with a known CVE (e.g., a remote code execution flaw in an older version of Log4j) exposes the application to potential attacks once exploit code becomes public. The decision based on 'wide usage' and 'no exploitation so far' is a fallacy, as threat actors often target widely deployed libraries precisely because of their large attack surface.

Exam trap

The trap here is that candidates may think 'no exploitation yet' means the risk is acceptable, but CISSP tests the principle that known vulnerabilities must be remediated regardless of current exploit status, as threat actors will eventually weaponize them.

How to eliminate wrong answers

Option A is wrong because insecure deserialization refers to the lack of validation on serialized objects (e.g., Java deserialization of untrusted data leading to RCE), which is a different vulnerability class not directly related to using a library with a known flaw. Option B is wrong because insufficient logging and monitoring is a failure to detect and respond to security events (e.g., not logging failed authentication attempts), not the decision to use a vulnerable component. Option D is wrong because security misconfiguration involves improper setup of security controls (e.g., default credentials, open cloud storage buckets), not the conscious choice to retain a library with a published CVE.

4
MCQmedium

A security analyst is reviewing the error handling of an application. The application currently displays detailed stack traces to users when an exception occurs. Which of the following is the best practice for error handling in production?

A.Display generic error messages to users and log detailed errors for admins
B.Display detailed errors to users for troubleshooting
C.Disable all error reporting to eliminate information leakage
D.Encrypt error messages before displaying to users
AnswerA

Displaying generic error messages like 'An unexpected error occurred' to users is a critical security practice that prevents the inadvertent disclosure of sensitive system information, such as database schemas, server configurations, or internal file paths. Concurrently, logging detailed error messages, including stack traces and specific error codes, for administrators is essential for effective debugging, incident response, and proactive identification of application vulnerabilities. This balanced approach ensures operational efficiency and maintainability without compromising the application's security posture by exposing internal workings to potential attackers.

Why this answer

Displaying generic error messages to users prevents attackers from learning internal details such as stack traces, file paths, database schema, or library versions that could be used to craft further attacks. Logging the detailed error information for administrators preserves the ability to troubleshoot and monitor without exposing sensitive data to end users. This separation of user-facing and admin-facing error detail is a fundamental secure coding practice.

Exam trap

CISSP often tests the confusion between 'no error reporting' and 'secure error reporting'—candidates may think disabling all errors is safest, but the correct answer preserves logging for admins while hiding details from users.

How to eliminate wrong answers

Option B is wrong because displaying detailed errors to users directly leaks implementation details (stack traces, SQL fragments, internal IPs) that enable reconnaissance and exploitation, which is the exact vulnerability being remediated. Option C is wrong because disabling all error reporting eliminates the audit and troubleshooting capability entirely, violating availability and monitoring requirements; errors should be logged, not suppressed. Option D is wrong because encrypting error messages before display is impractical and does not solve the problem—users would still receive ciphertext they cannot interpret, and the underlying information leakage risk remains if the key is compromised or the message is decrypted.

5
MCQeasy

During the requirements gathering phase of a software development project, which threat modeling methodology is most commonly used to identify threats such as spoofing, tampering, and elevation of privilege?

A.CVSS
B.STRIDE
C.OCTAVE
D.PASTA
AnswerB

STRIDE is a widely recognized threat modeling methodology developed by Microsoft, specifically designed to identify and categorize potential threats to a system during its design phase. Its acronym represents six distinct threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. These categories directly map to fundamental security properties like Authenticity, Integrity, Non-Repudiation, Confidentiality, Availability, and Authorization, making it highly effective for systematic threat identification in software.

Why this answer

STRIDE is a threat modeling methodology developed by Microsoft that categorizes threats into six types: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. During the requirements gathering phase, STRIDE is commonly used to systematically identify and classify potential security threats against each system component, making it the correct choice for identifying threats like spoofing, tampering, and elevation of privilege.

Exam trap

The trap here is that candidates often confuse CVSS (a scoring system) or OCTAVE (a risk assessment framework) with threat modeling methodologies, but the question specifically asks for the methodology most commonly used to identify threat types like spoofing and tampering, which is STRIDE.

How to eliminate wrong answers

Option A (CVSS) is wrong because CVSS (Common Vulnerability Scoring System) is a framework for scoring the severity of known vulnerabilities, not a threat modeling methodology used during requirements gathering to identify threats like spoofing or tampering. Option C (OCTAVE) is wrong because OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is a risk assessment framework focused on organizational risk and strategic planning, not a lightweight threat modeling technique for identifying specific threat types during software development requirements. Option D (PASTA) is wrong because PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling methodology that aligns business objectives with technical requirements, but it is not the most commonly used methodology for simply identifying threats like spoofing, tampering, and elevation of privilege during the requirements phase; STRIDE is more straightforward and widely adopted for that purpose.

6
Multi-Selectmedium

A security engineer is evaluating a web application for common vulnerabilities. The application uses a Content Management System (CMS) that is outdated and has known vulnerabilities. Additionally, the application displays detailed error messages and uses default administrative credentials. Which TWO of the following OWASP Top 10 categories are most relevant to these issues?

Select 2 answers
A.Vulnerable and Outdated Components
B.Security Misconfiguration
C.Injection
D.Cryptographic Failures
E.Broken Access Control
AnswersA, B

Vulnerable and Outdated Components refers to the risk posed by using software components, such as libraries, frameworks, and other modules, that have known security flaws or are no longer supported. Exploiting these vulnerabilities, often documented as Common Vulnerabilities and Exposures (CVEs), can grant attackers unauthorized access, data breaches, or system control. Regularly updating and patching all third-party components is crucial to mitigate this significant attack vector.

Why this answer

A is correct because the outdated CMS with known vulnerabilities directly corresponds to OWASP A06:2021 – Vulnerable and Outdated Components. This category covers using software versions with unpatched security flaws, which attackers can exploit via public exploit databases or automated scanners. B is correct because displaying detailed error messages and using default administrative credentials are classic examples of Security Misconfiguration (OWASP A05:2021).

This occurs when security settings are not properly defined, implemented, or maintained, allowing attackers to gain information or unauthorized access.

Exam trap

Candidates may incorrectly associate default credentials with Broken Access Control, but these are a security misconfiguration. The outdated CMS is clearly Vulnerable and Outdated Components.

7
MCQhard

A security architect is designing an authentication system. To prevent session fixation attacks, which secure design principle should be implemented?

A.Using HTTPS for all communications
B.Setting session timeout to 30 minutes
C.Implementing multi-factor authentication
D.Regenerating session IDs after successful login
AnswerD

Regenerating the session ID immediately after a user successfully authenticates is the most effective direct countermeasure against session fixation. This action ensures that any session ID an attacker might have previously forced upon the victim's browser becomes invalid and unusable. By issuing a completely new, cryptographically random session ID for the authenticated session, the application effectively severs the link between the attacker's known ID and the legitimate user's secure session, preventing unauthorized access.

Why this answer

Session fixation attacks occur when an attacker forces a user to use a known session ID. Regenerating the session ID after successful login (e.g., via `session_regenerate_id()` in PHP or `HttpServletRequest.changeSessionId()` in Java) ensures that the pre-authentication session ID is discarded and a new, unpredictable one is issued, breaking the attacker's control.

Exam trap

The trap here is that candidates confuse session fixation with session hijacking or general secure transmission, leading them to choose HTTPS or MFA, which are important but do not directly counter the fixation mechanism.

How to eliminate wrong answers

Option A is wrong because HTTPS encrypts data in transit but does not prevent an attacker from fixing a session ID before login; it protects against eavesdropping, not session fixation. Option B is wrong because setting a session timeout limits the window of opportunity for an attacker to use a fixed session, but it does not invalidate the fixed session ID after authentication; the attacker can still reuse it within the timeout period. Option C is wrong because multi-factor authentication strengthens identity verification but does not address the core issue of an attacker controlling the session ID; the fixed session ID remains valid even with MFA.

8
MCQhard

A developer is implementing cryptographic storage for sensitive user data. Which of the following is a cryptographic best practice?

A.Using a static initialization vector (IV) for all encryption operations
B.Encrypting data with a hardcoded key in source code
C.Hashing passwords with MD5 for performance
D.Using AES-256 in Galois/Counter Mode (GCM) for authenticated encryption
AnswerD

Using AES-256 in Galois/Counter Mode (GCM) for authenticated encryption represents a strong and recommended cryptographic best practice. AES-256 provides robust confidentiality with its 256-bit key, making brute-force attacks computationally infeasible. GCM, as an Authenticated Encryption with Associated Data (AEAD) mode, simultaneously ensures data integrity and authenticity by generating an authentication tag, which verifies that the ciphertext has not been tampered with and originated from a legitimate source. This combination offers comprehensive protection against both eavesdropping and active manipulation.

Why this answer

Industry-standard algorithms like AES-256 and SHA-256 are recommended, while MD5 and SHA-1 are deprecated due to weaknesses. Authenticated encryption (e.g., GCM) provides both confidentiality and integrity.

9
MCQmedium

During a security review of a web application, testers discover that the application discloses detailed error messages to users, including stack traces. Which secure coding best practice is being violated?

A.Input validation
B.Error handling
C.Secure logging
D.Output encoding
AnswerB

Proper error handling is the direct solution to preventing sensitive information disclosure through error messages. It mandates that applications gracefully intercept all exceptions and internal failures, subsequently presenting only generic, non-informative messages to end-users. Crucially, detailed diagnostic information, such as stack traces or database errors, must be securely logged on the server-side for administrators to troubleshoot, ensuring that no sensitive system details are inadvertently exposed to potential attackers or unauthorized individuals.

Why this answer

Detailed error messages with stack traces expose sensitive implementation details, which is a failure of proper error handling. Secure error handling requires generic user-facing messages while logging details internally. This prevents attackers from learning about the system's internals.

Exam trap

CISSP often tests the misconception that secure logging alone prevents information disclosure, when the core issue is the error handling mechanism that returns sensitive data to the user.

How to eliminate wrong answers

Option A is wrong because input validation focuses on rejecting malicious input, not on how errors are presented. Option C is wrong because secure logging is about protecting log data and ensuring it does not contain sensitive information, but the issue here is disclosure to users. Option D is wrong because output encoding prevents injection attacks like XSS, not information leakage via error messages.

10
MCQmedium

During a security assessment, a penetration tester discovers that a web application exposes internal IP addresses in error messages. Which vulnerability category does this represent?

A.Broken access control
B.Sensitive data exposure
C.Security misconfiguration
D.Insecure deserialization
AnswerC

Security misconfiguration is the correct classification because verbose error messages, which reveal internal IP addresses and potentially other system details like software versions or stack traces, are a direct result of improper system hardening. Production environments should be configured to suppress such detailed output, presenting only generic error messages to end-users. This prevents attackers from gathering valuable reconnaissance information that could facilitate further targeted attacks.

Why this answer

Exposing internal IP addresses in error messages is a classic example of a security misconfiguration (C). The web application is likely configured to output detailed error messages (e.g., stack traces or debug information) that include internal network details, which should be suppressed in production environments. This violates the principle of least information disclosure and is categorized under security misconfiguration because it stems from improper default or runtime settings.

Exam trap

The trap here is that candidates confuse the disclosure of internal IP addresses with 'sensitive data exposure' (B), but CISSP categorizes this under security misconfiguration because the root cause is a failure to properly configure error handling, not the inherent sensitivity of the data itself.

How to eliminate wrong answers

Option A is wrong because broken access control refers to failures in enforcing user permissions (e.g., accessing unauthorized resources via path traversal or privilege escalation), not the inadvertent disclosure of internal network information in error outputs. Option B is wrong because sensitive data exposure typically involves the exposure of protected data such as passwords, credit card numbers, or PII, whereas internal IP addresses are not classified as sensitive data under most regulatory frameworks (e.g., GDPR, PCI DSS) unless they reveal system architecture that could aid an attacker. Option D is wrong because insecure deserialization involves the manipulation of serialized objects to execute arbitrary code or bypass authentication, which is unrelated to the verbosity of error messages.

11
MCQmedium

A security analyst is reviewing a web application and notices that it includes a feature that allows users to view their own profile by providing a user ID in the URL (e.g., /profile?userid=123). The application does not verify that the logged-in user owns that profile. Which vulnerability is present?

A.Security misconfiguration
B.Cross-site scripting (XSS)
C.Insecure direct object reference (IDOR)
D.Cross-site request forgery (CSRF)
AnswerC

Insecure direct object reference (IDOR) occurs when a web application exposes a direct reference to an internal implementation object, such as a file, directory, or database key, and fails to verify that the user is authorized to access that object. Attackers can manipulate these references, often found in URL parameters or form fields, to access or modify data belonging to other users or system files. The scenario directly aligns with an IDOR vulnerability, as it involves bypassing authorization by directly referencing an object.

Why this answer

The application exposes an internal object reference (the userid parameter) and fails to perform an authorization check that the logged-in user owns that object. This is the textbook definition of an Insecure Direct Object Reference (IDOR), classified under OWASP as Broken Access Control (A01:2021). Because the URL directly maps to a backend record without an ownership check, an attacker can simply increment the userid value to view other users' profiles.

Exam trap

CISSP often tests the distinction between IDOR (missing object-level authorization) and CSRF (forged request using victim's session) — candidates confuse the two because both involve manipulating requests, but only IDOR exposes a direct object reference without an ownership check.

How to eliminate wrong answers

Option A is wrong because security misconfiguration refers to insecure defaults, verbose errors, or unnecessary features enabled (e.g., default credentials, directory listing), not a missing authorization check on an object reference. Option B is wrong because XSS involves injecting malicious client-side script that executes in another user's browser, whereas here the flaw is server-side access control, not script injection. Option D is wrong because CSRF tricks an authenticated user's browser into sending an unwanted request using their existing session; in this scenario the attacker is directly manipulating an object identifier, not forging a request via a victim's session.

12
MCQmedium

A security team is reviewing a web application that allows users to search for products. The application uses a SQL database and constructs queries by concatenating user input directly into the SQL statement. Which of the following is the most effective mitigation against SQL injection attacks?

A.Using parameterized queries with prepared statements
B.Escaping all user input before concatenation
C.Input validation using a blacklist of known malicious patterns
D.Implementing a Web Application Firewall (WAF)
AnswerA

Parameterized queries with prepared statements are the most effective defense against SQL injection because they fundamentally separate the SQL code structure from user-provided data. The database engine treats all input as literal values, not executable commands, preventing malicious input from altering the query's intent. This architectural separation ensures that special characters in user input are never interpreted as SQL syntax, thereby eliminating the injection vector at its root.

Why this answer

Parameterized queries with prepared statements separate SQL logic from user input by sending the query structure to the database first, then binding input values as data parameters. This prevents the database from interpreting user input as executable SQL code, even if the input contains malicious characters. It is the only defense that completely eliminates the injection vector at the database interaction layer.

Exam trap

The trap here is that candidates often choose input validation or escaping because they seem proactive, but the CISSP exam emphasizes that parameterized queries are the only definitive defense against SQL injection at the code level, as they enforce separation of code and data by design.

How to eliminate wrong answers

Option B is wrong because escaping user input is error-prone and context-dependent; an attacker can bypass escaping if the escape function is not perfectly aligned with the database's character set or query context (e.g., using alternate encodings or second-order injection). Option C is wrong because blacklist-based input validation can be circumvented by obfuscation techniques (e.g., using hex, Unicode, or case variations) and fails to block novel or unknown attack patterns. Option D is wrong because a WAF operates at the network or application layer and can only detect known attack signatures; it cannot prevent injection if the underlying code still concatenates input, and it can be bypassed by encoding or timing attacks.

13
MCQeasy

Which of the following is a secure coding practice to prevent SQL injection attacks?

A.Escaping all user input
B.Using parameterized queries
C.Using stored procedures exclusively
D.Validating input length
AnswerB

Parameterized queries, also known as prepared statements, are a highly effective secure coding practice for preventing SQL injection. They work by defining the SQL query structure with placeholders for data, which are then passed separately to the database engine. This strict separation ensures that user-supplied input is always treated as data values, never as executable SQL code, thus neutralizing any embedded malicious commands.

Why this answer

Parameterized queries (also known as prepared statements) separate SQL code from data by using placeholders (e.g., '?' in ODBC/JDBC or ':param' in Oracle) that are bound to user-supplied values at execution time. This ensures that input is always treated as data, never as executable SQL syntax, effectively neutralizing SQL injection regardless of the input content.

Exam trap

The trap here is that candidates often confuse 'stored procedures' with being inherently secure, but the CISSP exam tests that stored procedures can still be vulnerable if they use dynamic SQL with concatenated input, whereas parameterized queries (or prepared statements) are the definitive defense.

How to eliminate wrong answers

Option A is wrong because escaping all user input is error-prone and context-dependent; different database systems require different escape characters (e.g., backslash in MySQL vs. doubling single quotes in SQL Server), and incomplete or incorrect escaping can still allow injection. Option C is wrong because stored procedures alone do not prevent SQL injection if they contain dynamic SQL built with string concatenation (e.g., EXECUTE IMMEDIATE in Oracle or sp_executesql with concatenated parameters in SQL Server). Option D is wrong because validating input length only restricts the size of the input, not its content; an attacker can still inject malicious SQL within a valid length limit (e.g., a 10-character string like '1 OR 1=1').

14
MCQhard

A company is evaluating a third-party software library for use in their application. Which document provides a detailed inventory of the library's components and dependencies to help assess supply chain risk?

A.Service Level Agreement (SLA)
B.Data processing agreement
C.Vulnerability disclosure report
D.Software Bill of Materials (SBOM)
AnswerD

A Software Bill of Materials (SBOM) is a formal, machine-readable inventory of all software components, including open-source and commercial elements, and their dependencies used in a product. It provides critical transparency into the software supply chain, enabling organizations to proactively identify and track known vulnerabilities, licensing obligations, and potential risks associated with third-party libraries, which is essential for comprehensive risk assessment.

Why this answer

A Software Bill of Materials (SBOM) is a machine-readable inventory of all components, libraries, and dependencies in a software artifact, including versions and suppliers. It is the primary document for assessing supply chain risk because it reveals transitive dependencies that may contain known vulnerabilities.

Exam trap

CISSP often tests whether candidates confuse SBOM with vulnerability reports or SLAs — the trap is picking 'vulnerability disclosure report' because it sounds security-related, when the question asks specifically for a component and dependency inventory.

How to eliminate wrong answers

Option A is wrong because an SLA defines service performance and availability commitments between provider and customer, not component inventory. Option B is wrong because a data processing agreement governs how personal data is handled under privacy law (e.g., GDPR Article 28), not software composition. Option C is wrong because a vulnerability disclosure report describes known vulnerabilities and disclosure timelines, but it does not enumerate the full component inventory needed for supply chain analysis.

15
MCQeasy

Which type of security testing involves analyzing source code for vulnerabilities without executing the code?

A.SAST
B.Penetration testing
C.IAST
D.DAST
AnswerA

SAST (Static Application Security Testing) is a white-box testing methodology that directly analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the program. It identifies potential flaws such as SQL injection, cross-site scripting (XSS), buffer overflows, and insecure direct object references by examining code patterns and data flows. This static analysis occurs early in the Software Development Life Cycle (SDLC), allowing developers to fix issues before deployment.

Why this answer

SAST (Static Application Security Testing) analyzes source code, bytecode, or binary code for security vulnerabilities without executing the program. It operates by scanning the codebase for patterns known to be insecure (e.g., SQL injection via string concatenation) using techniques like data flow analysis, taint tracking, and pattern matching, all performed at rest.

Exam trap

The trap here is that candidates confuse SAST with DAST because both are 'security testing' acronyms, but the key differentiator is that SAST analyzes code without execution (static), while DAST requires a running application (dynamic).

How to eliminate wrong answers

Option B is wrong because penetration testing is a dynamic, manual or automated process that tests a running application or system by simulating attacks, not by analyzing static source code. Option C is wrong because IAST (Interactive Application Security Testing) combines static and dynamic analysis by instrumenting the application and monitoring its behavior during runtime execution, not by analyzing code without execution. Option D is wrong because DAST (Dynamic Application Security Testing) tests an application while it is running, typically by sending malicious payloads and observing responses, which requires execution and does not involve source code analysis.

16
MCQhard

During a penetration test, a security analyst discovers that a web application allows an attacker to bypass authorization and view another user's private messages by simply changing a numeric ID in the URL. Which vulnerability is being exploited?

A.Broken authentication
B.Insecure direct object reference (IDOR)
C.Server-side request forgery (SSRF)
D.Security misconfiguration
AnswerB

Insecure direct object reference (IDOR) occurs when an application exposes a direct reference to an internal implementation object, such as a file, database key, or directory, and fails to implement sufficient authorization checks. An attacker can manipulate these references, often found in URL parameters or request bodies, to access or modify resources belonging to other users or system components without explicit permission. This directly aligns with a penetration test discovery where an analyst accesses unauthorized objects by altering an identifier.

Why this answer

B is correct because the vulnerability allows an attacker to access another user's private messages by simply changing a numeric ID in the URL, which is a classic example of Insecure Direct Object Reference (IDOR). This occurs when the application exposes a direct reference to an internal object (e.g., a database key) without proper access control checks, enabling unauthorized access to resources belonging to other users.

Exam trap

The trap here is that candidates confuse IDOR with broken authentication because both involve unauthorized access, but IDOR specifically targets direct object references without proper access controls, whereas broken authentication focuses on flaws in the authentication process itself.

How to eliminate wrong answers

Option A is wrong because broken authentication refers to flaws in session management, credential handling, or login mechanisms (e.g., weak password policies, session fixation), not the direct manipulation of object references in URLs. Option C is wrong because Server-Side Request Forgery (SSRF) involves an attacker inducing the server to make requests to internal or external resources, not directly accessing another user's data via a modified URL parameter. Option D is wrong because security misconfiguration covers issues like default credentials, unnecessary services, or verbose error messages, but does not specifically describe the lack of authorization checks on object references.

17
MCQeasy

Which of the following is the primary purpose of output encoding in web application security?

A.Preventing buffer overflow attacks
B.Preventing cross-site request forgery (CSRF)
C.Preventing cross-site scripting (XSS) attacks
D.Preventing SQL injection attacks
AnswerC

Output encoding is the fundamental defense against cross-site scripting (XSS) attacks, which involve injecting malicious client-side scripts into web pages. By transforming potentially dangerous characters like angle brackets (<, >) and quotes (", ') into their safe entity equivalents (e.g., &lt;, &gt;), output encoding ensures that user-supplied input is always interpreted as inert data. This prevents the browser from executing the injected content as active code, thereby neutralizing the XSS payload before it can affect other users.

Why this answer

Output encoding is the practice of converting special characters (e.g., <, >, &, ") into their corresponding HTML entities (e.g., &lt; &gt; &amp; &quot;) before sending data to the browser. This ensures that any user-supplied data is treated as text, not executable code, thereby neutralizing injected scripts. It is the primary defense against stored, reflected, and DOM-based cross-site scripting (XSS) attacks because it breaks the parser's ability to interpret the data as active content.

Exam trap

The trap here is that candidates confuse output encoding with input validation or sanitization, mistakenly thinking it prevents SQL injection or CSRF, but output encoding only neutralizes XSS by ensuring data is rendered as text in the browser, not as executable code.

How to eliminate wrong answers

Option A is wrong because buffer overflow attacks are prevented by bounds checking, input validation, and safe memory functions (e.g., strncpy instead of strcpy), not by output encoding, which operates on output to browsers, not on memory buffers. Option B is wrong because CSRF is prevented by anti-CSRF tokens (e.g., synchronizer tokens or SameSite cookies), not by output encoding, which does not validate the origin or authenticity of requests. Option D is wrong because SQL injection is prevented by parameterized queries (prepared statements) or stored procedures, not by output encoding, which applies to HTML/JavaScript contexts, not to database query construction.

18
Multi-Selectmedium

A security engineer is hardening a web server before deploying a new application. Which TWO of the following are examples of security misconfiguration vulnerabilities that should be addressed?

Select 2 answers
A.Use of an outdated version of a JavaScript library with known vulnerabilities
B.Default administrator credentials remain unchanged
C.Verbose error messages reveal stack traces to users
D.Lack of CSRF tokens in forms
E.Weak password policy allowing short passwords
AnswersB, C

Leaving default administrator credentials unchanged is a quintessential example of a security misconfiguration. These credentials are often publicly known or easily guessable, providing attackers with a straightforward entry point if not immediately altered post-installation. Proper hardening requires modifying all default passwords and usernames to unique, strong values, ensuring the system's initial setup doesn't become its weakest link.

Why this answer

Option B is correct because leaving default administrator credentials unchanged is a classic security misconfiguration: the system is deployed with vendor-supplied accounts (e.g., admin/admin) that attackers can trivially guess, and hardening requires changing or disabling them. Option C is correct because verbose error messages that expose stack traces, framework versions, or file paths are a misconfiguration of error handling and debug settings (e.g., ASP.NET customErrors=Off or Django DEBUG=True), leaking information useful for further attacks. Option A does not belong because using an outdated JavaScript library with known CVEs is a vulnerable component/software supply chain issue, not a configuration error.

Option D does not belong because missing CSRF tokens is a code-level application flaw (broken access/request forgery protection), not a misconfiguration. Option E does not belong because a weak password policy is an authentication/identity policy weakness rather than a system or server misconfiguration.

Exam trap

The CISSP exam often tests the distinction between 'security misconfiguration' and other vulnerability types (e.g., using outdated libraries is a 'using components with known vulnerabilities' issue, not a misconfiguration), so candidates mistakenly classify all common weaknesses as misconfigurations.

19
Multi-Selecthard

A security team is performing a risk assessment on a legacy application that uses insecure deserialization. Which TWO of the following are recommended approaches to mitigate the risk of insecure deserialization?

Select 2 answers
A.Implementing integrity checks (e.g., digital signatures) on serialized objects
B.Encrypting the serialized data
C.Using allow lists for classes that can be deserialized
D.Using generic exception handling to catch errors
E.Logging all deserialization attempts
AnswersA, C

A digital signature, applied by the sender, creates a cryptographic hash of the serialized object and encrypts it with the sender's private key. Upon deserialization, the receiver can verify this signature using the sender's public key and the sender's public key certificate. This process cryptographically guarantees that the serialized data has not been altered in transit, preventing an attacker from injecting malicious code or modifying object properties before deserialization occurs.

Why this answer

Option A is correct because applying integrity checks such as digital signatures or HMACs to serialized objects lets the receiving application verify that the data was not tampered with before deserialization, preventing attackers from injecting malicious serialized payloads. Option C is correct because an allow list (whitelist) restricts deserialization to only explicitly permitted, trusted classes, blocking the instantiation of dangerous gadget classes that enable remote code execution. Option B is not recommended as a primary mitigation because encryption provides confidentiality but does not prevent an attacker who can supply or replay ciphertext from triggering malicious deserialization, and it does not validate object integrity or class types.

Option D is not appropriate because generic exception handling only masks errors and does not stop malicious objects from being deserialized and executed. Option E is not a mitigation because logging deserialization attempts is a detective control that records activity but does not prevent exploitation.

Exam trap

The trap here is that candidates often confuse encryption with integrity protection, thinking that encrypting serialized data prevents tampering, but encryption alone does not provide authentication or integrity — an attacker can still modify ciphertext (bit-flipping attacks) unless combined with a MAC or digital signature.

20
MCQmedium

A development team is designing a new application and wants to ensure that if a failure occurs, the system remains secure by default. Which design principle should they apply?

A.Least privilege
B.Defense in depth
C.Separation of duties
D.Fail-secure
AnswerD

Fail-secure, also known as fail-safe, is a critical design principle ensuring that if a system component or process fails, the system defaults to a state that denies access or prevents operations, thus maintaining security. For instance, a locked door remains locked if power fails, or an authentication system denies all access if its backend database becomes unavailable. This approach prioritizes security over availability during a failure event, directly addressing how an application should behave to protect data and resources.

Why this answer

Fail-secure is the design principle that dictates a system should default to a secure state when it fails — for example, denying access, locking doors, or dropping connections rather than allowing them. It directly addresses the requirement that 'if a failure occurs, the system remains secure by default.' The other principles address access scope, layered controls, and fraud prevention, not failure behavior.

Exam trap

The trap here is confusing fail-secure (secure on failure) with fail-safe/fail-open (available on failure) — CISSP often swaps these terms to test whether you know the security-vs-availability trade-off.

How to eliminate wrong answers

Option A is wrong because least privilege limits what an authenticated subject can do, but says nothing about what happens when the system itself fails. Option B is wrong because defense in depth is about layering multiple controls so no single failure compromises security — it is a strategy, not the specific failure-mode behavior described. Option C is wrong because separation of duties prevents one person from completing a sensitive transaction alone; it does not define system failure behavior.

21
MCQmedium

A security architect is reviewing a design for an e-commerce application. The architect recommends implementing defense in depth. Which of the following is an example of this principle?

A.Encrypting data at rest only
B.Implementing both a web application firewall (WAF) and input validation
C.Using a single firewall at the network perimeter
D.Requiring strong passwords for all users
AnswerB

This option correctly demonstrates defense in depth by combining two distinct and complementary security controls. A Web Application Firewall (WAF) provides an external, perimeter-like defense, filtering malicious requests before they reach the application server, while input validation acts as an internal, application-level control, ensuring that only safe and properly formatted data is processed. This layered approach significantly reduces the attack surface and effectively mitigates a broader spectrum of web-based threats, such as SQL injection and cross-site scripting, by providing multiple points of enforcement.

Why this answer

Defense in depth layers multiple independent controls so that failure of one does not compromise the system. A WAF filters malicious HTTP traffic at the application layer, while input validation rejects malformed or malicious data at the code layer; together they provide overlapping protections against injection and web attacks. This is a textbook example of layered, complementary controls.

Exam trap

CISSP often tests the misconception that any single strong control (encryption, firewall, passwords) constitutes defense in depth, when the principle requires multiple independent layers.

How to eliminate wrong answers

Option A is wrong because encrypting data at rest only protects stored data and provides no protection against network, application, or insider threats, so it is a single control rather than layered defense. Option C is wrong because a single perimeter firewall is a single point of failure and does not address internal threats, application-layer attacks, or lateral movement. Option D is wrong because strong passwords are one authentication control and do not constitute multiple layers of defense across different attack surfaces.

22
MCQeasy

A software development team is preparing to release a new application. The security manager requires that the application be tested for security vulnerabilities before deployment. Which of the following testing approaches is specifically designed to simulate real-world attacks against a running application?

A.Dynamic Application Security Testing (DAST)
B.Interactive Application Security Testing (IAST)
C.Static Application Security Testing (SAST)
D.Software Composition Analysis (SCA)
AnswerA

DAST tests a running application from the outside, simulating attacks similar to those a real attacker would use. It can identify vulnerabilities such as injection, authentication flaws, and misconfigurations that only appear at runtime. This directly meets the requirement to test for security vulnerabilities by simulating real-world attacks against the deployed application.

Why this answer

Dynamic Application Security Testing (DAST) is designed to simulate real-world attacks by testing a running application from the outside. It identifies vulnerabilities that manifest at runtime, such as input validation errors and authentication flaws. Unlike SAST or SCA, DAST actively probes the application as an attacker would, making it the appropriate choice for this requirement.

Exam trap

The trap here is confusing DAST with other testing methods like SAST or IAST, which do not simulate external attacks against a running application.

23
MCQmedium

A development team is implementing a web application that allows users to search for products. To prevent SQL injection attacks, which secure coding practice should be applied?

A.Input validation using a blacklist of SQL keywords
B.Parameterized queries with prepared statements
C.Output encoding of user input
D.Using stored procedures exclusively
AnswerB

Parameterized queries with prepared statements are the most effective defense against SQL injection vulnerabilities. By separating the SQL code from user-supplied data, the database engine can distinguish between the query structure and the values to be inserted, updated, or retrieved. This mechanism ensures that user input is always treated as literal data, preventing it from being interpreted as executable SQL commands.

Why this answer

Parameterized queries with prepared statements (Option B) are the definitive defense against SQL injection because they separate SQL logic from user-supplied data. The database engine compiles the query structure first, then binds input values as parameters, ensuring that malicious input cannot alter the intended SQL command. This approach is language-agnostic and works across all modern database interfaces (e.g., JDBC, PDO, ADO.NET).

Exam trap

The trap here is that candidates often confuse stored procedures as a silver bullet for SQL injection, failing to realize that the security lies in how parameters are bound, not in the procedure container itself.

How to eliminate wrong answers

Option A is wrong because blacklisting SQL keywords is inherently incomplete and easily bypassed; attackers can use encoding, comments, or alternative syntax (e.g., CHAR(), CONCAT()) to evade the filter. Option C is wrong because output encoding (e.g., HTML entity encoding) is designed to prevent cross-site scripting (XSS), not SQL injection, which occurs at the database layer before output is rendered. Option D is wrong because stored procedures alone do not prevent SQL injection if dynamic SQL is constructed within the procedure; the protection comes only when parameters are used inside the stored procedure, not from the procedure itself.

24
MCQhard

A development team is implementing cryptographic functions for a new application. They need to store passwords securely. Which of the following is the most appropriate approach?

A.Use a key derivation function (e.g., bcrypt) with a per-user salt
B.Encrypt passwords using AES-256 with a static key
C.Store passwords in plaintext but in a protected database
D.Hash passwords with SHA-256 without salt
AnswerA

Using a key derivation function (KDF) like bcrypt with a per-user salt is the most secure method for storing passwords. Bcrypt is specifically designed to be computationally intensive and slow, making brute-force attacks economically infeasible by requiring significant processing power for each guess. The unique, randomly generated per-user salt ensures that even identical passwords produce different hashes, effectively neutralizing precomputed rainbow table attacks and dictionary attacks across multiple user accounts.

Why this answer

Passwords must be stored using a slow, salted, adaptive key derivation function such as bcrypt, scrypt, Argon2, or PBKDF2. A per-user salt prevents rainbow-table and precomputation attacks, and the deliberately slow work factor makes brute-force and GPU-accelerated cracking impractical. bcrypt with a per-user salt is the canonical correct answer for secure password storage.

Exam trap

CISSP often tests the confusion between hashing and encryption for passwords — candidates pick AES encryption thinking it is 'stronger,' missing that reversibility is the fatal flaw, and they underestimate how fast unsalted SHA-256 can be brute-forced.

How to eliminate wrong answers

Option B is wrong because encrypting passwords with AES-256 using a static key is reversible — anyone who obtains the key can decrypt all passwords, and a static key shared across the application is a single point of catastrophic failure. Option C is wrong because storing passwords in plaintext, even in a 'protected' database, means a single database breach exposes every credential directly; this violates every password-storage standard (NIST SP 800-63B, OWASP ASVS). Option D is wrong because SHA-256 without salt is a fast general-purpose hash vulnerable to rainbow tables and GPU brute-force (billions of hashes per second), and identical passwords produce identical hashes, enabling credential-stuffing correlation.

25
Multi-Selectmedium

A security architect is reviewing a web application's design and identifies several potential vulnerabilities. Which TWO of the following are effective mitigations for cross-site scripting (XSS) attacks?

Select 2 answers
A.Enabling Content Security Policy (CSP)
B.Using CSRF tokens
C.Disabling client-side scripts entirely
D.Implementing parameterized queries
E.Using output encoding
AnswersA, E

Content Security Policy (CSP) is a crucial security mechanism that allows web administrators to define trusted sources for content, such as scripts, stylesheets, and images, that a user agent is permitted to load for a given page. By restricting script execution to only approved origins, CSP significantly mitigates Cross-Site Scripting (XSS) attacks, preventing browsers from executing malicious scripts injected from untrusted sources, even if an injection vulnerability exists. This policy acts as a powerful, browser-enforced second layer of defense.

Why this answer

Option A, enabling Content Security Policy (CSP), is correct because CSP is a browser-enforced response header (e.g., Content-Security-Policy: default-src 'self') that restricts which scripts may execute, blocking inline scripts and untrusted external sources, which directly mitigates XSS. Option E, using output encoding, is correct because encoding untrusted data for the correct context (HTML entity, JavaScript, URL, or CSS encoding) ensures injected markup is rendered as inert text rather than executable script, which is the primary defense against XSS. Option B, using CSRF tokens, does not belong because anti-CSRF tokens defend against cross-site request forgery, a different attack that abuses a victim's authenticated session, not script injection.

Option C, disabling client-side scripts entirely, does not belong because it is an impractical, functionality-breaking measure rather than a targeted XSS mitigation and is not a standard remediation. Option D, implementing parameterized queries, does not belong because prepared statements with bound parameters mitigate SQL injection, not XSS.

Exam trap

CISSP often mixes injection attack mitigations, so candidates who see 'parameterized queries' reflexively associate it with all injection flaws and incorrectly apply it to XSS instead of SQL injection.

26
MCQhard

A development team is fixing a stored cross-site scripting (XSS) vulnerability in a web application that displays user comments. The application stores comments in a database and renders them in HTML. Which of the following is the most secure approach to prevent XSS?

A.Use Content Security Policy (CSP) headers to restrict script execution
B.Sanitize input by removing all HTML tags before storing
C.Apply output encoding based on the context (e.g., HTML entity encoding)
D.Store comments in a separate domain to isolate them
AnswerC

Applying output encoding, specifically HTML entity encoding for HTML contexts, is the most effective and robust solution for preventing stored Cross-Site Scripting (XSS). This process transforms malicious characters (like <, >, &, ", ') into their safe, non-executable representations before rendering them in the browser. By ensuring that user-supplied data is treated as data, not executable code, the browser interprets the encoded script as harmless text, thereby neutralizing the XSS payload.

Why this answer

Output encoding (C) is the most secure approach because it neutralizes malicious scripts at the point of rendering, ensuring that user-controlled data is treated as text rather than executable code. For HTML contexts, HTML entity encoding (e.g., `&lt;script&gt;`) prevents the browser from interpreting injected tags, regardless of how the data was stored. This aligns with the defense-in-depth principle and is the primary mitigation for stored XSS as recommended by OWASP.

Exam trap

A common misconception is that input sanitization (removing tags) is the best approach, but the CISSP emphasizes that output encoding is the definitive control because it works regardless of how data enters the system and preserves data integrity for legitimate use.

How to eliminate wrong answers

Option A is wrong because CSP is a defense-in-depth layer that can restrict script execution, but it does not fix the root cause—malicious data remains in the database and could still be exploited if CSP is misconfigured or bypassed (e.g., via JSONP or older browser versions). Option B is wrong because removing all HTML tags before storing destroys legitimate formatting (e.g., bold, lists) and is overly restrictive; a more nuanced sanitization (e.g., whitelist-based) is possible, but output encoding is still needed as a final safeguard. Option D is wrong because storing comments on a separate domain does not prevent XSS—the comments are still rendered in the original application's HTML context, and the same-domain origin policy does not block script execution from injected content.

27
MCQeasy

What is the primary purpose of a Web Application Firewall (WAF) in a deployment environment?

A.Encrypting all web traffic
B.Filtering malicious HTTP traffic
C.Managing user authentication
D.Performing vulnerability scanning
AnswerB

Filtering malicious HTTP traffic is the core and primary purpose of a Web Application Firewall (WAF). A WAF inspects incoming HTTP/HTTPS requests and outgoing responses at the application layer (Layer 7) for signatures and behaviors indicative of common web attacks, such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 threats. By analyzing the content, headers, and parameters, the WAF can block or alert on malicious requests before they reach the web application, thereby protecting it from exploitation.

Why this answer

A WAF inspects inbound HTTP/HTTPS requests at Layer 7 and blocks those matching known attack signatures or anomalous patterns, such as SQL injection, cross-site scripting, and malformed requests. It sits in front of a web application (for example, on Azure Application Gateway or Front Door) and enforces rule sets like the OWASP Core Rule Set. Its defining purpose is application-layer traffic filtering, not transport encryption or identity management.

Exam trap

The trap here is confusing the WAF's Layer 7 filtering role with adjacent security functions — encryption (TLS), authentication (IdP), and scanning (vulnerability management) — all of which are handled by different components in a defense-in-depth architecture.

How to eliminate wrong answers

Option A is wrong because encryption of web traffic is provided by TLS termination at the load balancer, gateway, or web server — a WAF may inspect decrypted traffic but does not itself encrypt it. Option C is wrong because user authentication is handled by identity providers, federation protocols (SAML, OIDC), or application code, not by a WAF's filtering rules. Option D is wrong because vulnerability scanning is a separate assessment activity performed by tools like Qualys, Nessus, or Defender for Cloud; a WAF mitigates exploitation attempts at runtime rather than discovering vulnerabilities.

28
MCQmedium

During a threat modeling session for a new online banking application, the team uses the STRIDE methodology. Which threat category addresses the risk of an attacker modifying transaction data in transit?

A.Information Disclosure
B.Tampering
C.Elevation of Privilege
D.Spoofing
AnswerB

Tampering specifically refers to the unauthorized modification or alteration of data, whether in transit or at rest, within an application or system. For an online banking application, this could manifest as an attacker changing transaction amounts, recipient details, account balances, or system logs, directly compromising the integrity of financial data and operational processes. This threat directly targets the trustworthiness and accuracy of information, making it a primary concern for financial systems.

Why this answer

STRIDE's Tampering category covers unauthorized modification of data, whether at rest or in transit. Modifying transaction data in transit is the textbook definition of tampering, which violates integrity. The other categories map to different security properties: Information Disclosure to confidentiality, Spoofing to authentication, and Elevation of Privilege to authorization.

Exam trap

CISSP often tests the mapping between STRIDE categories and the CIA/AAA properties they violate; candidates confuse Tampering (integrity) with Spoofing (authentication) or Information Disclosure (confidentiality) when the scenario mentions 'data in transit'.

How to eliminate wrong answers

Option A is wrong because Information Disclosure addresses unauthorized reading/exposure of data (confidentiality breach), not modification. Option C is wrong because Elevation of Privilege describes an attacker gaining higher access rights than authorized, not altering data in transit. Option D is wrong because Spoofing involves impersonating a user, system, or process to gain trust, not modifying the payload itself.

29
MCQhard

During a vulnerability assessment, a security analyst discovers that a web application uses a library known to be vulnerable to Log4Shell (CVE-2021-44228). Which type of vulnerability does this represent?

A.Server-side request forgery (SSRF)
B.Vulnerable components
C.Insecure deserialization
D.Security misconfiguration
AnswerB

Vulnerable components refer to weaknesses found within third-party libraries, frameworks, or modules that are integrated into an application. The Log4Shell vulnerability (CVE-2021-44228) is a quintessential example, where a critical remote code execution flaw existed within the widely used Apache Log4j logging library itself. Discovering a flaw in a logging library directly aligns with identifying a vulnerable component, as the application's security posture is compromised by a defect in one of its constituent parts.

Why this answer

Log4Shell (CVE-2021-44228) is a remote code execution flaw in the Apache Log4j 2 library's JNDI lookup feature. Because the vulnerability resides in a third-party dependency that the application includes, it is classified under OWASP Top 10 A06:2021 — Vulnerable and Outdated Components. The application code itself may be fine; the risk comes from the library version it ships with.

Exam trap

CISSP often tests the confusion between 'the app has a bug' and 'the app uses a buggy library' — candidates pick SSRF or deserialization because Log4Shell's exploit path resembles those, missing that the vulnerability classification is about the component, not the attack technique.

How to eliminate wrong answers

Option A is wrong because SSRF involves the server being tricked into making requests to unintended destinations — while Log4Shell's JNDI lookup can be leveraged for SSRF-like behavior, the root vulnerability class is the vulnerable component, not SSRF. Option C is wrong because insecure deserialization refers to untrusted data being deserialized into objects (e.g., Java ObjectInputStream, Python pickle) — Log4Shell exploits a JNDI lookup, not a deserialization sink. Option D is wrong because security misconfiguration refers to improperly configured servers, frameworks, or cloud services (default credentials, verbose errors, open buckets), not a flaw in a library's code.

30
MCQeasy

Which of the following is an example of an Insecure Direct Object Reference (IDOR) vulnerability?

A.An attacker intercepts session cookies to impersonate a user
B.An attacker uses a SQL injection to retrieve data from the database
C.An attacker submits a cross-site request forgery (CSRF) token to perform actions
D.An attacker changes the user ID parameter in a URL to view another user's profile
AnswerD

This is a classic example of an Insecure Direct Object Reference (IDOR). The application directly exposes a reference to an internal implementation object, such as a user ID in a URL parameter, without adequately verifying the user's authorization to access that specific object. By simply modifying the user ID parameter, the attacker can bypass access controls and retrieve or manipulate data belonging to other users, demonstrating a critical authorization flaw.

Why this answer

IDOR occurs when an application exposes an internal object reference, such as a user ID in a URL, and fails to verify that the requester is authorized to access that object. Changing the user ID parameter to view another user's profile is the textbook example of this broken access control flaw.

Exam trap

CISSP often tests the distinction between access control flaws and injection or session attacks, so the trap is picking SQL injection or session hijacking when the scenario describes manipulating an object reference.

How to eliminate wrong answers

Option A is wrong because intercepting session cookies is session hijacking, not IDOR. Option B is wrong because SQL injection exploits unsanitized input to manipulate database queries, which is a different vulnerability class. Option C is wrong because submitting a CSRF token describes a cross-site request forgery scenario, not direct object reference manipulation.

31
MCQmedium

During the requirements gathering phase of a secure SDLC, the team uses a threat modeling approach that focuses on identifying threats such as spoofing, tampering, and denial of service. Which threat modeling methodology is being employed?

A.PASTA
B.Trike
C.STRIDE
D.OCTAVE
AnswerC

STRIDE is a mnemonic developed by Microsoft that provides a systematic framework for categorizing and identifying common types of threats against software and systems. Each letter represents a specific threat category: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. This framework is exceptionally useful during the requirements gathering phase of the SDLC to proactively identify potential vulnerabilities and design security controls that directly mitigate these well-defined threat types.

Why this answer

STRIDE is a threat modeling methodology developed by Microsoft that categorizes threats into six types: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. The question explicitly mentions spoofing, tampering, and denial of service, which are three of the STRIDE categories. Therefore, STRIDE is the correct answer.

Exam trap

CISSP often tests the confusion between threat modeling methodologies like STRIDE, PASTA, Trike, and OCTAVE, where candidates may pick a methodology based on familiarity rather than matching the specific threat categories mentioned in the question.

How to eliminate wrong answers

Option A is wrong because PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric, seven-step threat modeling methodology that focuses on aligning business objectives with technical requirements, not on categorizing threats by type like spoofing or tampering. Option B is wrong because Trike is a threat modeling framework that uses a risk-based approach with a focus on satisfying security requirements and is not organized around the specific threat categories mentioned. Option D is wrong because OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is a risk assessment methodology that focuses on organizational risk, not on categorizing threats into spoofing, tampering, etc.

32
MCQeasy

A security architect is designing a system that must continue to function even when a component fails. The architect implements multiple layers of security controls so that if one fails, others still provide protection. Which principle is being applied?

A.Separation of duties
B.Defense in depth
C.Fail-secure
D.Least privilege
AnswerB

This robust security strategy involves implementing multiple, independent, and overlapping security controls across various layers of an information system's architecture. By integrating administrative, technical, and physical safeguards, it ensures that if one control fails or is circumvented, other controls are still in place to detect, delay, or prevent an attack. This layered approach significantly increases the complexity and resources required for an adversary to achieve their objectives.

Why this answer

Defense in depth (B) is the correct principle because it involves implementing multiple layers of security controls (e.g., firewalls, intrusion detection systems, encryption, access controls) so that if one layer fails or is bypassed, other layers continue to provide protection, ensuring the system remains functional. This directly matches the scenario where the architect designs for continued operation despite component failure by layering controls.

Exam trap

The trap here is that candidates confuse 'defense in depth' with 'fail-secure' because both involve planning for failure, but fail-secure prioritizes security over availability (e.g., locking down on failure) whereas defense in depth prioritizes continued operation through redundancy of controls.

How to eliminate wrong answers

Option A is wrong because separation of duty is a principle that prevents fraud or error by requiring multiple individuals to complete a sensitive task (e.g., one person authorizes, another executes), not by layering controls for resilience. Option C is wrong because fail-secure means that when a component fails, the system defaults to a secure state (e.g., locking all doors on power loss), which may actually halt functionality rather than ensure continued operation. Option D is wrong because least privilege restricts users or processes to only the minimum permissions needed to perform their tasks, which is a access control principle unrelated to maintaining function during component failures.

33
Multi-Selectmedium

During a code review, a developer identifies that the application uses a custom encryption algorithm for storing sensitive data. Which THREE of the following are secure cryptographic practices that should be recommended instead?

Select 3 answers
A.Using industry-standard algorithms (e.g., AES-256)
B.Implementing proper key management practices
C.Using authenticated encryption (e.g., AES-GCM)
D.Hashing the data with MD5 for faster performance
E.Using a static IV for simplicity
AnswersA, B, C

Industry-standard cryptographic algorithms like AES-256 undergo extensive public scrutiny and cryptanalysis by experts worldwide. This rigorous vetting process helps identify and mitigate potential vulnerabilities, ensuring their robustness against known attack methods and providing a high level of confidence in their security. Relying on such well-established algorithms is fundamental for achieving strong confidentiality and integrity in data protection, as opposed to proprietary or unproven methods.

Why this answer

Option A is correct because industry-standard, peer-reviewed algorithms such as AES-256 have undergone extensive cryptanalysis and are the accepted baseline for symmetric encryption, unlike custom algorithms that typically contain undiscovered weaknesses. Option B is correct because even a strong algorithm like AES is useless if keys are hardcoded, reused, or stored insecurely; proper key management (secure generation, rotation, storage in HSMs/KMS, and separation of duties) is essential to protect sensitive data. Option C is correct because authenticated encryption such as AES-GCM provides both confidentiality and integrity/authenticity, preventing tampering and padding-oracle style attacks that unauthenticated modes like AES-CBC are vulnerable to.

Option D is not recommended because MD5 is a broken hash (collisions demonstrated) and hashing is not encryption—it is unsuitable for protecting data that must be retrieved. Option E is not recommended because a static IV causes identical plaintexts to produce identical ciphertexts, leaking patterns and enabling replay or chosen-plaintext attacks; IVs must be unique/random per encryption operation.

Exam trap

The trap here is that candidates may think 'any encryption is better than none' or that 'hashing is a form of encryption,' but the CISSP exam emphasizes that custom algorithms and broken hashes like MD5 are never acceptable for protecting sensitive data, and that proper cryptographic practices require standards, key management, and authenticated modes.

34
Multi-Selecteasy

A security analyst is reviewing the authentication mechanism of a web application. Which TWO of the following are examples of broken authentication vulnerabilities?

Select 2 answers
A.Insecure direct object reference in profile URLs
B.Verbose error messages disclosing user IDs
C.Lack of multi-factor authentication for sensitive actions
D.Session timeout set to 60 minutes
E.Allowing weak passwords without complexity requirements
AnswersC, E

The absence of multi-factor authentication (MFA) for sensitive actions constitutes a significant broken authentication vulnerability. MFA requires users to provide two or more distinct verification factors to gain access, substantially increasing the difficulty for unauthorized users to compromise an account even if one factor (like a password) is stolen. Without MFA, a single compromised credential can grant full access to critical functions, directly weakening the authentication process for high-value operations.

Why this answer

Option C is correct because the absence of multi-factor authentication for sensitive actions is a classic broken authentication weakness: it means a stolen or guessed password alone is sufficient to perform high-risk operations, which OWASP categorizes under broken authentication (e.g., credential stuffing and brute-force success). Option E is correct because permitting weak passwords without complexity or length requirements directly enables brute-force, dictionary, and credential-stuffing attacks against the authentication mechanism, another core broken authentication flaw. Option A is not a broken authentication issue but an access control flaw (IDOR), which falls under broken access control.

Option B describes information disclosure via verbose errors, which is a misconfiguration/information-leakage issue rather than an authentication weakness. Option D, a 60-minute session timeout, is a session management hardening consideration but is not inherently a broken authentication vulnerability, since it is a configurable policy choice rather than a defect in the authentication process itself.

Exam trap

CISSP often tests whether candidates can distinguish authentication failures from access control failures, so they incorrectly select IDOR or verbose errors as broken authentication.

35
Multi-Selectmedium

A security analyst is reviewing a web application that handles financial transactions. Which TWO of the following are effective controls against Cross-Site Request Forgery (CSRF)?

Select 2 answers
A.Setting cookies with the SameSite attribute to Strict
B.Using anti-CSRF tokens in forms
C.Using HTTPS for all pages
D.Enforcing strong password policies
E.Implementing input validation on all user inputs
AnswersA, B

The SameSite=Strict attribute on cookies ensures that the browser will only send the cookie with requests originating from the same site as the cookie's domain. This effectively prevents a malicious third-party site from tricking a user's browser into sending authenticated requests to the legitimate application, thereby mitigating Cross-Site Request Forgery (CSRF) attacks. It provides a robust defense by restricting cookie transmission to first-party contexts only.

Why this answer

Option A is correct because setting cookies with the SameSite attribute to Strict prevents the browser from sending the session cookie on cross-site requests, which blocks the CSRF attack vector since the attacker's forged request lacks the victim's authentication cookie. Option B is correct because anti-CSRF tokens (synchronizer tokens) are unique, unpredictable values embedded in forms and validated server-side, ensuring that a request originates from the legitimate application page rather than a forged cross-site request. Option C is not correct because HTTPS only encrypts data in transit and does not prevent a browser from automatically attaching credentials to a forged request.

Option D is not correct because strong password policies address credential guessing and brute-force attacks, not the abuse of an already-authenticated session. Option E is not correct because input validation mitigates injection flaws like XSS or SQLi, but does not stop a forged request that contains valid, expected input.

Exam trap

CISSP often tests the misconception that HTTPS or input validation prevents CSRF — candidates must recognize that CSRF is an origin/authorization problem, not a confidentiality or injection problem, so only token-based and SameSite controls address it.

36
MCQeasy

A software development team is adopting secure coding practices. They decide to implement input validation for all user-supplied data. Which approach is recommended as the most effective for preventing injection attacks?

A.Encoding input before processing
B.Using regular expressions to sanitize input
C.Blacklist validation to block known malicious patterns
D.Whitelist validation to allow only known good patterns
AnswerD

Whitelist validation is considered the most robust and secure approach for handling user input. This method explicitly defines and permits only a specific set of known-good, expected characters, formats, or values that the application is designed to accept. Any input that deviates from this precisely defined safe set is rejected by default. This proactive "allow-by-default" strategy effectively prevents unknown or novel attack vectors, as anything not explicitly allowed is implicitly denied, making it highly resilient against various injection and manipulation attempts.

Why this answer

Whitelist (allowlist) validation defines exactly what input is acceptable and rejects everything else, which is the most robust defense against injection because it does not depend on enumerating every possible attack pattern. Attackers constantly invent new encodings and payload variants, so an allowlist of known-good characters, formats, or values is far more reliable than trying to block known-bad input.

Exam trap

CISSP often tests the allowlist-versus-blacklist distinction by offering plausible-sounding alternatives like encoding or regex sanitization — the trap is choosing a mechanism (encoding, regex) over the correct validation strategy (positive/allowlist validation).

How to eliminate wrong answers

Option A is wrong because encoding is an output-handling defense applied at the point of use (e.g., HTML/URL/SQL encoding) to neutralize special characters — it is not input validation and does not by itself prevent injection if the data is later used unsafely. Option B is wrong because regular expressions are a mechanism, not a strategy; regex-based sanitization that strips 'bad' characters is still blacklist-style and is prone to bypass via encoding, Unicode normalization, or regex flaws. Option C is wrong because blacklist validation only blocks patterns the developer already knows about, so any novel or obfuscated payload evades it — it is explicitly discouraged by OWASP.

37
Multi-Selectmedium

An organization is planning to acquire a new SaaS application for customer relationship management. Which THREE of the following should be included in the vendor security assessment?

Select 3 answers
A.Checking license compliance for open source components
B.Reviewing the vendor's security certifications (e.g., SOC 2, ISO 27001)
C.Requesting a Software Bill of Materials (SBOM)
D.Assessing the vendor's incident response process
E.Requiring employee security training records
AnswersB, C, D

Reviewing a vendor's security certifications, such as SOC 2 or ISO 27001, provides independent assurance that the vendor has implemented and maintains robust security controls. These certifications indicate that an external auditor has verified the effectiveness of the vendor's information security management system (ISMS) against recognized standards. This offers critical insight into the vendor's commitment to security, data protection, and operational resilience, significantly reducing the acquiring organization's due diligence burden.

Why this answer

Option B is correct because reviewing the vendor's security certifications such as SOC 2 and ISO 27001 provides independent attestation that the SaaS provider has implemented and audited controls for security, availability, and confidentiality, which is essential when entrusting customer data to a third party. Option C is correct because requesting a Software Bill of Materials (SBOM) gives visibility into the open source and third-party components in the SaaS application, enabling the organization to assess supply chain risk and quickly identify exposure to known vulnerabilities such as those tracked in CVE databases. Option D is correct because assessing the vendor's incident response process verifies that the provider has defined detection, notification, containment, and recovery procedures, which is critical for meeting the organization's own breach notification and business continuity obligations.

Option A is not included because license compliance for open source components is a legal and procurement concern rather than a core vendor security control assessment. Option E is not included because requiring employee security training records is an internal personnel control and does not directly evaluate the security posture of the SaaS vendor's service.

Exam trap

CISSP often tests the distinction between security-relevant vendor due diligence (certifications, SBOM, IR) and tangential operational or legal items (license compliance, employee training records) that sound plausible but are not part of a security assessment.

38
MCQmedium

A web application exposes an API that allows users to fetch data from internal network resources based on a URL parameter. An attacker discovers they can use this API to access internal servers that are not meant to be public. Which vulnerability is being exploited?

A.Insecure direct object reference (IDOR)
B.Remote code execution (RCE)
C.Cross-site request forgery (CSRF)
D.Server-side request forgery (SSRF)
AnswerD

SSRF is exactly this pattern: the API accepts a user-supplied URL or parameter and the server-side code then fetches that resource on the caller's behalf. Because the request originates from the server, it inherits the server's network position and often bypasses firewall rules that would block a direct external request. Attackers abuse this to reach internal-only services, cloud metadata endpoints, or other systems that were never intended to be reachable from outside the network perimeter.

Why this answer

SSRF allows an attacker to induce the server to make requests to internal or external resources, bypassing firewalls and access controls.

39
Multi-Selectmedium

During a security audit of a web application, the following issues are found: (1) Session tokens are included in URLs, (2) The application does not invalidate session tokens after logout, and (3) Session tokens are predictable. Which THREE of the following controls are most appropriate to address these issues?

Select 3 answers
A.Regenerate session tokens after login
B.Store session tokens in cookies with Secure and HttpOnly flags
C.Invalidate session tokens on logout and set short expiration times
D.Use a cryptographically secure random number generator for token generation
E.Implement IP address binding for session tokens
AnswersB, C, D

Storing session tokens in cookies with the Secure flag ensures they are only transmitted over encrypted HTTPS connections, preventing passive network eavesdropping. The HttpOnly flag prevents client-side scripts, such as JavaScript, from accessing the cookie's content, significantly mitigating the risk of session token theft via Cross-Site Scripting (XSS) attacks. These flags collectively enhance the confidentiality and integrity of session tokens during transit and storage.

Why this answer

Option B is correct because storing session tokens in cookies with Secure and HttpOnly flags addresses the issue of tokens being included in URLs by keeping them out of URLs and providing additional protections. Option C is correct because invalidating session tokens on logout and setting short expiration times directly addresses the lack of invalidation. Option D is correct because using a cryptographically secure random number generator directly addresses the predictability of session tokens.

Option A is incorrect because regenerating session tokens after login is primarily a control against session fixation, not directly addressing predictability, exposure in URLs, or lack of invalidation. Option E is incorrect because IP address binding is fragile and does not protect against token exposure or poor invalidation.

Exam trap

ISC2 often tests the misconception that IP binding is a strong session management control, but in reality it is fragile and not a primary defense against session token exposure, predictability, or improper invalidation.

40
Multi-Selecthard

A security team is planning to integrate security testing into the software development lifecycle. They want to identify vulnerabilities early and often. Which TWO of the following testing methods should be implemented during the development phase (before deployment) to catch code-level vulnerabilities?

Select 2 answers
A.Interactive Application Security Testing (IAST)
B.Penetration testing
C.Vulnerability scanning
D.Static Application Security Testing (SAST)
E.Dynamic Application Security Testing (DAST)
AnswersA, D

IAST is a modern security testing method that instruments the application code and observes its behavior from within during automated or manual functional tests. It provides real-time analysis of application interactions, identifying vulnerabilities with high accuracy by understanding both code execution and data flow. This integration into existing testing processes makes it highly effective for finding flaws early in the development lifecycle.

Why this answer

Option A, Interactive Application Security Testing (IAST), is correct because it instruments the running application (often via agents during automated tests) to analyze code execution in real time, detecting code-level vulnerabilities such as injection flaws early in the development phase before deployment. Option D, Static Application Security Testing (SAST), is correct because it performs white-box analysis of source code, bytecode, or binaries without executing the program, allowing developers to find flaws like SQL injection or hardcoded secrets directly in the code during development. Penetration testing (B) is typically conducted against a deployed, running system and simulates real-world attacks, so it occurs later than the development phase.

Vulnerability scanning (C) identifies known weaknesses in deployed hosts, services, and configurations rather than code-level defects during development. Dynamic Application Security Testing (E) tests a running application from the outside (black-box) and is generally performed after deployment or in a staging environment, not as an early code-level check.

Exam trap

CISSP often tests the phase confusion between SAST/IAST (development-time, code-level) and DAST/pen testing/vulnerability scanning (deployment-time, runtime or infrastructure), so candidates must map each tool to the correct SDLC phase.

41
MCQmedium

A security team is conducting a penetration test on a web application. They identify that the application is vulnerable to reflected cross-site scripting (XSS). Which of the following is the most effective mitigation?

A.Using HTTPS to encrypt traffic
B.Implementing a Content Security Policy (CSP) with strict directives
C.Validating input against a whitelist of allowed characters
D.Encoding all user-supplied data before reflecting it in the response
AnswerD

Encoding all user-supplied data before reflecting it in the response is the primary and most effective defense against reflected Cross-Site Scripting (XSS) attacks. This process transforms potentially malicious characters (e.g., '<', '>', '&') into their safe, non-executable HTML entity equivalents (e.g., '&lt;', '&gt;', '&amp;'). By ensuring the browser interprets user input as inert data rather than executable code, this practice directly prevents the injection and execution of malicious scripts within the user's browser.

Why this answer

Reflecting user-supplied data without proper encoding allows an attacker to inject arbitrary HTML/JavaScript that executes in the victim's browser. Output encoding (e.g., HTML entity encoding for context like <script> to &lt;script&gt;) neutralizes the injected script by treating it as data rather than executable code. This directly addresses the root cause of reflected XSS—failure to separate user input from executable content in the response.

Exam trap

The trap here is that candidates often confuse input validation (Option C) with output encoding, but the CISSP emphasizes that output encoding is the definitive control for injection flaws because it ensures data is treated as data regardless of input validation failures.

How to eliminate wrong answers

Option A is wrong because HTTPS encrypts data in transit but does not prevent the server from reflecting malicious input in the response; the XSS payload still executes in the browser after decryption. Option B is wrong because while CSP can mitigate XSS by restricting script sources, it is a defense-in-depth control and not the most effective primary mitigation—it can be bypassed if the application reflects user input into inline script contexts or if CSP is misconfigured (e.g., using 'unsafe-inline'). Option C is wrong because input validation against a whitelist is effective for input validation but does not guarantee safety when data is reflected; an attacker may bypass the whitelist or inject via other input channels, and output encoding is required regardless of input validation.

42
Multi-Selecthard

A security architect is defining security requirements for a new software development project that will use an Agile methodology. The organization wants to ensure that security is integrated throughout the development lifecycle. Which TWO of the following practices BEST support this goal? (Choose two.)

Select 2 answers
A.Document security requirements in a large specification document at the project start.
B.Require the security team to manually review all code changes before deployment.
C.Integrate automated static analysis security testing (SAST) into the CI/CD pipeline.
D.Conduct threat modeling sessions at the beginning of each sprint for new features.
E.Perform a full penetration test only at the end of the project before release.
AnswersC, D

Automated SAST in the CI/CD pipeline provides continuous code analysis, catching vulnerabilities as code is committed. This aligns with Agile's fast iterations and enables developers to fix issues immediately. It scales security across the team without slowing down delivery, making it a best practice for integrating security into the development lifecycle.

Why this answer

Threat modeling at each sprint and automated SAST in the CI/CD pipeline both embed security into Agile's iterative cycles. Threat modeling addresses design flaws early, while SAST provides continuous code-level checks. Together, they enable rapid feedback and remediation, which are essential for integrating security throughout the development lifecycle without impeding Agile delivery.

Exam trap

The trap here is assuming that a single end-of-project penetration test or manual code reviews constitute sufficient security integration in Agile.

Ready to test yourself?

Try a timed practice session using only Software Development Security questions.