โ† All CCP Flashcard Decks

Application Security & Secure Coding Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Application Security & Secure Coding flashcards as text
  1. Which application security testing technique analyzes source code for vulnerabilities without executing the program?

    Answer: Static Application Security Testing (SAST)

    SAST examines source code, bytecode, or binary code for security weaknesses at rest, without running the application.

  2. Cross-Site Request Forgery (CSRF) attacks are best defended against using which mechanism?

    Answer: Anti-CSRF tokens synchronized between client and server

    Anti-CSRF (synchronizer) tokens are unique, secret values embedded in forms that the server validates on submission, ensuring the request originated from the legitimate site.

  3. Which of the following best describes the principle of least privilege as applied to application design?

    Answer: Allowing applications to request only the permissions they need to function

    Least privilege in application design means components and users are granted only the minimum access rights required to perform their function, limiting damage from compromise.

  4. Which API security best practice prevents attackers from enumerating all resources by exploiting predictable identifiers?

    Answer: Implementing rate limiting and randomized resource identifiers

    Rate limiting prevents automated enumeration, and randomized (non-sequential) identifiers make it impractical to guess valid resource IDs.

  5. A developer logs full exception stack traces to the end user when an error occurs. What security risk does this create?

    Answer: Information disclosure that aids attacker reconnaissance

    Detailed stack traces expose internal file paths, library versions, and logic, giving attackers valuable intelligence to craft targeted exploits.

  6. Which secure coding practice best reduces the risk from third-party library vulnerabilities in application dependencies?

    Answer: Regularly auditing and updating dependencies using a software composition analysis tool

    Software Composition Analysis (SCA) tools continuously monitor dependencies for known CVEs and prompt timely patching when vulnerabilities are disclosed.

  7. In secure session management, what is the recommended action immediately after a user successfully authenticates?

    Answer: Issue a new session ID to prevent session fixation attacks

    Generating a new session ID after authentication prevents session fixation, where an attacker pre-sets a known session ID to hijack the session after the user logs in.