Application Security & Secure Coding Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Application Security & Secure Coding flashcards as text
Which vulnerability class occurs when an application deserializes untrusted data, allowing attackers to execute arbitrary code?
Answer: Insecure Deserialization
Insecure Deserialization allows attackers to manipulate serialized objects to alter application logic or achieve remote code execution during the deserialization process.
Which threat modeling framework uses the categories Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
Answer: STRIDE
STRIDE is a Microsoft-developed threat classification model where each letter represents a category of security threat used to identify risks during design.
A race condition vulnerability in a banking application allows two simultaneous withdrawals to each succeed against a single balance. What class of flaw is this?
Answer: Time-of-Check to Time-of-Use (TOCTOU)
TOCTOU (Time-of-Check to Time-of-Use) is a race condition where the state of a resource changes between validation and use, enabling double-spending or similar exploits.
Which DevSecOps practice integrates automated security scanning directly into the CI/CD pipeline?
Answer: Shifting security left by embedding SAST/DAST scans in build and deploy stages
Shifting security left means integrating automated security tools (SAST, DAST, SCA) into CI/CD pipelines so vulnerabilities are detected and fixed during development, not after release.
An attacker sends a crafted XML document containing an external entity reference that causes the server to read a local file. Which vulnerability is being exploited?
Answer: XXE (XML External Entity) Injection
XXE Injection exploits XML parsers that process external entity declarations, allowing attackers to read local files, perform SSRF, or execute denial-of-service attacks.
Which secure coding principle dictates that security controls should fail in a safe manner, denying access when an error occurs?
Answer: Fail-Safe Defaults
Fail-Safe Defaults means that when a system fails or encounters an error, it defaults to a secure state (access denied) rather than an insecure state (access granted).
Which approach to application security testing simulates real-world attackers by actively probing a running application for exploitable vulnerabilities?
Answer: Dynamic Application Security Testing (DAST)
DAST tests the running application from the outside by simulating attacker behavior, identifying vulnerabilities like injection flaws and authentication weaknesses that only appear at runtime.