CompTIA Study Materials
AWS Study Materials
AWS Cloud Practitioner AWS Cloud Practitioner
AWS Cloud Practitioner CLF-C02
Microsoft Study Materials
Microsoft Azure Fundamentals Microsoft Azure Fundamentals
Microsoft Azure Fundamentals AZ-900

Free CompTIA PenTest+ PT0-002 Practice Question

During a penetration testing engagement, you have identified that a client's web application is vulnerable to code injection attacks due to the lack of input validation. Which recommendation would best align with integrating security practices into the client's software development life cycle?

  • Advise the client to implement regular key rotation policies to mitigate the code injection attack.

  • Urge the client to enforce mandatory staff vacations to reduce the risk of insider threats which may lead to code injection vulnerabilities.

  • Suggest the implementation of better certificate management practices to secure the web application against code injection.

  • Propose the addition of more comprehensive user training programs to prevent code injection attacks.

  • Recommend that the development team incorporates input validation and parameterized queries into their coding standards to prevent similar vulnerabilities in future releases.

This question is for objective:
Reporting and Communication
Your Score:
Reporting and Communication
Information Gathering and Vulnerability Scanning
Attacks and Exploits
Tools and Code Analysis
Planning and Scoping