CCT Application Security & Secure Coding Flashcards
6 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCT Application Security & Secure Coding flashcards as text
Which OWASP Top 10 vulnerability occurs when untrusted data is sent to an interpreter as part of a command or query?
Answer: Injection
Injection flaws, such as SQL injection, occur when untrusted data is sent to an interpreter as part of a command or query, allowing attackers to execute unintended commands.
What is the primary purpose of input validation in secure application development?
Answer: Prevent malicious data from being processed
Input validation ensures that only properly formed data enters a system, preventing malicious input from causing vulnerabilities like injection attacks or buffer overflows.
Which secure coding practice prevents Cross-Site Scripting (XSS) attacks?
Answer: Output encoding and input sanitization
Output encoding ensures that user-supplied data is treated as data rather than executable code, while input sanitization removes or neutralizes potentially malicious characters.
What does a Content Security Policy (CSP) header primarily protect against?
Answer: Cross-Site Scripting (XSS)
CSP is a browser security mechanism that restricts which resources can be loaded, significantly reducing the risk and impact of XSS attacks by whitelisting trusted content sources.
In secure software development, what is the principle of 'least privilege' as applied to application accounts?
Answer: Applications should have only the minimum permissions needed to function
Least privilege limits an application's access rights to only what is necessary, reducing the potential damage if the application is compromised.
What is a parameterized query (prepared statement) used to prevent?
Answer: SQL injection attacks
Parameterized queries separate SQL code from data, ensuring user input is always treated as a literal value and never interpreted as SQL syntax.