Courseiva
mediumMultiple Select

CISSP Practice Question: Which THREE of the following are key practices in…

Which THREE of the following are key practices in the OWASP ASVS (Application Security Verification Standard) for secure software? (Select exactly three.)

⚠ Common exam trap

Candidates often confuse general security best practices (like network segmentation or password manager integration) with the specific, application-focused requirements of OWASP ASVS, which is strictly about software security verification at the code and design level, not infrastructure or external tool integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secure error handling and logging

Option A (Secure error handling and logging) is correct because ASVS V7 requires applications to handle errors safely and log security-relevant events without leaking sensitive data such as stack traces, credentials, or internal paths. Option C (Authentication and session management) is correct because ASVS V2 and V3 define requirements for credential storage, password policies, MFA, session token entropy, and session invalidation. Option E (Input validation and sanitization) is correct because ASVS V5 mandates server-side input validation and output encoding to prevent injection flaws like SQLi and XSS. Option B (Integration with password managers) is not an ASVS practice; ASVS addresses password handling requirements, not client-side password manager integration. Option D (Network segmentation between tiers) is not part of ASVS, which focuses on application-level security requirements rather than infrastructure network architecture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Secure error handling and logging

    Why this is correct

    Secure error handling and logging are critical OWASP practices that prevent applications from leaking sensitive system information, such as stack traces or database errors, which attackers could exploit. Concurrently, robust logging captures security-relevant events, including failed authentication attempts and access violations, enabling timely detection and response to security incidents. This aligns directly with OWASP ASVS V7 requirements for comprehensive error handling and logging mechanisms.

  • ✗

    Integration with password managers

    Why it's wrong here

    While integrating with password managers enhances user convenience and promotes strong password usage, it is not considered a core application security practice directly mandated by OWASP's primary frameworks like the ASVS or Top 10. OWASP focuses on securing the application itself, including its authentication mechanisms and code, rather than dictating specific client-side tools users should employ for credential management.

  • ✓

    Authentication and session management

    Why this is correct

    Authentication and session management are fundamental OWASP practices, crucial for verifying user identities and securely maintaining their state across multiple requests. OWASP ASVS V2 details requirements for robust authentication controls, including multi-factor authentication and secure credential storage, while V3 addresses secure session management, covering aspects like session token generation, expiration, and invalidation to prevent unauthorized access and session hijacking.

  • ✗

    Network segmentation between tiers

    Why it's wrong here

    Network segmentation between application tiers, such as separating web, application, and database servers, is a vital infrastructure security control that limits the blast radius of attacks. However, OWASP's primary focus, particularly in frameworks like the ASVS, is on securing the application layer itself, its code, and its direct interactions. While complementary, network segmentation falls under network architecture and operational security, not direct application security practices.

  • ✓

    Input validation and sanitization

    Why this is correct

    Input validation and sanitization are cornerstone OWASP practices designed to prevent a wide array of injection attacks, including SQL injection, Cross-Site Scripting (XSS), and command injection. By rigorously checking, filtering, and encoding all user-supplied data against expected formats and safe characters, applications can ensure data integrity and prevent malicious payloads from being processed or stored. OWASP ASVS V5 specifically outlines comprehensive requirements for robust input validation at all trust boundaries.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.