CCT Application Security & Secure Coding Flashcards
6 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCT Application Security & Secure Coding flashcards as text
What is Dynamic Application Security Testing (DAST)?
Answer: Testing a running application from the outside to find vulnerabilities
DAST tools test a running application by simulating external attacks, finding vulnerabilities that only manifest during execution, such as authentication issues and runtime errors.
What does a Cross-Site Request Forgery (CSRF) attack exploit?
Answer: The trust a website has in a user's browser session
CSRF tricks authenticated users into unknowingly submitting malicious requests by exploiting the trust a web application places in the user's authenticated browser session.
Which of the following is the best defense against CSRF attacks?
Answer: Implementing anti-CSRF tokens in forms
Anti-CSRF tokens are unique, secret, and unpredictable values tied to a user's session that must be included in state-changing requests, making forged requests from other sites invalid.
What is the purpose of a Web Application Firewall (WAF)?
Answer: Filter, monitor, and block malicious HTTP/HTTPS traffic targeting web applications
A WAF inspects HTTP/HTTPS requests and responses against rule sets to detect and block common web application attacks like SQLi, XSS, and CSRF before they reach the application.
What is the role of threat modeling in secure application development?
Answer: Identifying potential threats and vulnerabilities in an application's design
Threat modeling is a structured process for identifying security threats, attack vectors, and countermeasures during the design phase before any code is written.
What does 'security by obscurity' mean and why is it considered insufficient?
Answer: Relying on secrecy of design or implementation as the main security mechanism, which fails once the secret is exposed
Security by obscurity relies on hiding how a system works rather than using genuine security controls, which provides no protection once an attacker discovers or leaks the design.