ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During security testing of a new RESTful microservice, the QA team captures legitimate production JSON requests and wants to create fuzz inputs quickly without first defining a complete protocol grammar. Which approach to developing fuzz test cases best satisfies these constraints?
Interactive application security testing (IAST) with runtime instrumentation
Static application security testing (SAST) of the service's source code
Mutated fuzzing that alters the captured JSON requests to produce unexpected variations
Generated fuzzing that relies on a grammar describing every JSON field and data type
Mutated fuzzing is designed for situations where testers already have valid sample inputs but lack a detailed formal specification of the protocol or file format. The technique works by randomly modifying (mutating) the captured requests-changing field values, lengths, encoding, or order-to create large numbers of test cases that can expose parsing crashes, injection flaws, and other defects. Generated fuzzing requires a model or grammar of the JSON API, so it has a higher upfront cost that contradicts the team's need for speed. Static and interactive application security testing examine source code or instrumentation during runtime; they are useful but do not fulfill the specific requirement of producing many malformed inputs from existing samples.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is fuzz testing in security?
Open an interactive chat with Bash
Why is mutated fuzzing faster than grammar-based fuzzing?
Open an interactive chat with Bash
How does fuzz testing differ from other security testing methods like SAST and IAST?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .