easyMultiple Select
CISSP Practice Question: Which TWO of the following are secure coding…
Which TWO of the following are secure coding practices to prevent buffer overflow vulnerabilities?
⚠ Common exam trap
Candidates often confuse compiler-level mitigations like stack protection with network-level controls, or mistakenly believe that dynamic memory allocation (C) inherently prevents overflows, when in fact unbounded dynamic allocation is a primary source of heap-based buffer overflows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Input validation.
Input validation (B) is a core secure coding practice because it ensures that data entering a program is checked for type, length, format, and range before being processed, so oversized or malformed input cannot be written past the boundaries of a fixed-size buffer. Use of compilers with stack protection (E) is also correct because mechanisms such as stack canaries (e.g., -fstack-protector in GCC/Clang) detect and abort execution when a return address or saved frame pointer has been overwritten, mitigating classic stack-based buffer overflows. The other options do not belong: code obfuscation (A) only makes code harder to read and provides no memory-safety benefit, dynamic memory allocation without bounds (C) actually increases overflow risk by failing to limit how much data is written, and unsafe functions like strcpy (D) perform no length checking and are a well-known cause of buffer overflows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Code obfuscation.
Why it's wrong here
Code obfuscation aims to make code harder to understand or reverse-engineer, typically by renaming variables, encrypting strings, or altering control flow. While it can deter some forms of analysis, it does not modify the underlying memory management or input handling logic. Consequently, obfuscation offers no direct protection against buffer overflow vulnerabilities, as the flaw still exists in the program's execution regardless of its readability. It's a security-by-obscurity measure, not a preventative control against memory corruption.
- ✓
Input validation.
Why this is correct
Input validation is a fundamental secure coding practice that involves rigorously checking user-supplied data against predefined criteria before processing it. For buffer overflows, this means verifying the length, type, and format of all inputs to ensure they do not exceed the allocated buffer size. By rejecting or truncating oversized inputs, input validation directly prevents data from spilling beyond its intended memory boundaries, thereby eliminating a common vector for buffer overflow attacks.
- ✗
Dynamic memory allocation without bounds.
Why it's wrong here
Dynamic memory allocation, while flexible, does not inherently provide protection against buffer overflows, especially when performed without proper bounds checking. Allocating memory with functions like `malloc` or `new` only reserves a block of memory; it does not automatically prevent subsequent write operations from exceeding that block's boundaries if the application logic fails to enforce limits. Without explicit checks on the size of data being written into dynamically allocated buffers, an attacker can still exploit an overflow to corrupt adjacent memory.
- ✗
Use of unsafe functions like strcpy.
Why it's wrong here
The use of unsafe functions, such as `strcpy`, `strcat`, `sprintf`, and `gets`, is a primary cause of buffer overflow vulnerabilities, not a prevention. These functions operate without performing bounds checking on the destination buffer, meaning they will blindly copy or concatenate data until a null terminator is encountered or the source data is exhausted, regardless of the destination buffer's capacity. This inherent lack of boundary awareness makes them extremely dangerous and prone to memory corruption when handling untrusted input.
- ✓
Use of compilers with stack protection.
Why this is correct
Compilers equipped with stack protection features, such as stack canaries, implement runtime mechanisms to detect and mitigate stack-based buffer overflows. A stack canary is a small, secret value placed on the stack between the buffer and control data (like the return address). If a buffer overflow occurs and overwrites the canary, the program detects the alteration before returning from the function, triggering an error and terminating execution to prevent potential exploit execution. This provides a crucial layer of defense against common overflow attacks.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
Secure coding
Secure coding is the practice of writing software in a way that protects it from vulnerabilities and attacks by following security best practices throughout the development process.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.