ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While reviewing an application's end-user documentation you observe that it instructs support staff to leave the default behavior in which database exceptions such as "ORA-01017: invalid username/password; logon denied" are displayed directly to users. From a security documentation standpoint, which corrective action should you recommend to mitigate the primary risk this practice introduces?
Revise the guide to mandate replacing specific database error codes with generic user messages, recording full details only in secured server logs.
Expand the documentation to include a comprehensive appendix of all database error codes so users can diagnose issues themselves.
Direct developers to turn off structured exception handling so that the web server returns standard HTTP 500 pages whenever a failure occurs.
Keep the current behavior but instruct users to capture and email screenshots of any error dialog to the help desk for analysis.
Detailed backend error codes can reveal implementation details that help attackers craft targeted exploits (e.g., identifying the database engine or authentication logic). The recommended fix is to change both the code and accompanying documentation so that end users receive only generic, non-informative error messages, while complete diagnostic details are captured in protected server-side logs for administrators. Simply listing all possible error codes for users, disabling exception handling, or asking users to send screenshots leaves sensitive information exposed or degrades availability without addressing information disclosure.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why should detailed error codes be hidden from end users?
Open an interactive chat with Bash
How can error messages be handled securely in applications?
Open an interactive chat with Bash
What are secured server logs and how do they protect sensitive information?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .