ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
In a peer code review, you find a utility class that checks the HTTP header X-Admin-Token against the hard-coded value 9beef42. If it matches, the code calls grantAdministrator() and bypasses normal authentication and audit logging. This behavior is undocumented and unknown to operations staff. Which type of malicious code does this most likely represent?
Race condition caused by unsynchronized authentication calls
Rootkit designed to conceal malicious processes
Logic bomb that activates under specific conditions to damage data
The code provides an undocumented mechanism that allows anyone who knows the magic token to gain privileged access while bypassing ordinary controls. This fits the definition of a backdoor: hidden functionality intentionally inserted to give unauthorized users a way into the system. A logic bomb requires a specific trigger but usually performs a destructive action rather than silent access. A rootkit hides the presence of malicious processes on a running system, which is not shown here. A race condition is a flaw related to concurrent execution timing, not deliberate hidden access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a backdoor in software security?
Open an interactive chat with Bash
How does a logic bomb differ from a backdoor?
Open an interactive chat with Bash
Why is hardcoding sensitive values, like X-Admin-Token, a security risk?
Open an interactive chat with Bash
What is a backdoor in software?
Open an interactive chat with Bash
How does a backdoor differ from a rootkit?
Open an interactive chat with Bash
Why is hard-coded authentication a security risk, and how can it be avoided?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .