ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During triaging of a recent penetration-test report, you discover a flaw where unsanitized user input is concatenated directly into SQL statements, enabling data exfiltration. When entering this item into the team's security bug-tracking system, how should you classify it to ensure it receives the correct severity scoring and remediation priority?
Classify it as a defect, because it fails to meet functional specifications.
Classify it as a vulnerability, since it is an exploitable weakness that threatens the system's security.
Classify it as an improvement, because replacing string concatenation with parameterized queries enhances performance but is not mandatory.
Classify it as an error, because it originated from a developer's coding mistake.
Because the flaw can be directly exploited to compromise confidentiality, integrity, or availability, it meets the definition of a security vulnerability. Recording it explicitly as a vulnerability distinguishes it from routine coding errors or non-security functional defects and avoids downplaying its impact. Once labeled as a vulnerability, a standardized severity framework such as CVSS can be applied, and the organization can then incorporate any additional business context to prioritize remediation. Classifying it merely as an error, generic defect, or "improvement" would obscure its security implications and likely delay necessary fixes.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SQL injection, and why is it considered a vulnerability?
Open an interactive chat with Bash
What is CVSS, and how does it help in scoring vulnerabilities?
Open an interactive chat with Bash
How do parameterized queries differ from regular concatenated SQL queries?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .