Refer to the exhibit. During static testing, a tester identifies that the 'lockout_duration_mins' is set to 15. What is the most likely risk identified by the tester?
Static analysis of the policy involves comparing it to the project's security requirements. Whether 15 minutes is appropriate depends on the application's risk profile. The tester's role is to ensure the team validates this configuration against business and security goals before it is implemented in the actual code.
Why this answer
A static review of security policies identifies vulnerabilities before they are deployed. A 15-minute lockout might be too short for effective brute-force protection or too long for legitimate user usability, depending on the risk model. Identifying these policy gaps during the design phase allows the team to adjust security settings to balance security and usability without requiring costly code changes post-deployment.
Exam trap
Candidates often assume a specific configuration value like 15 minutes is inherently correct or incorrect without realizing that static testing requires reviewing it against business and security requirements.