ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a security-focused sprint review, a tester submits an excessively long string in a search field and causes an unhandled exception that returns a complete Java stack trace to the user, exposing file paths and class names. Under a formal security bug-tracking taxonomy, how should the team record this finding to ensure proper risk prioritisation?
Record it as a defect, because it is a coding flaw affecting normal functionality rather than security.
Log it as an enhancement request, because suppressing stack traces would merely improve user experience, not security.
Record it as a vulnerability, since it creates an information-disclosure weakness that attackers could exploit.
Record it as an error, since it reflects a developer's mistake that happens before code execution.
The unhandled exception exposes internal implementation details to any user, giving attackers useful reconnaissance information. Because the flaw is not merely a coding fault (defect) or a human slip (error) but a weakness that could be exploited to compromise confidentiality, it meets the definition of a vulnerability and should be tracked as such. Defect would under-state the security significance, error refers to the underlying human mistake rather than the exposed condition, and an enhancement request would deprioritise remediation entirely.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is revealing a Java stack trace a security vulnerability?
Open an interactive chat with Bash
How is a vulnerability different from a defect or error?
Open an interactive chat with Bash
How should the team prevent unhandled exceptions from exposing internal details?
Open an interactive chat with Bash
Why is exposing a Java stack trace considered a vulnerability?
Open an interactive chat with Bash
What is the difference between a vulnerability and a defect in security taxonomy?
Open an interactive chat with Bash
How can unhandled exceptions be mitigated to prevent information disclosure?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .