CompTIA PenTest+ PT0-002 Practice Question

During a penetration testing engagement, you have identified that a client's web application is vulnerable to code injection attacks due to the lack of input validation. Which recommendation would best align with integrating security practices into the client's software development life cycle?

  • Urge the client to enforce mandatory staff vacations to reduce the risk of insider threats which may lead to code injection vulnerabilities.

  • Suggest the implementation of better certificate management practices to secure the web application against code injection.

  • Propose the addition of more comprehensive user training programs to prevent code injection attacks.

  • Advise the client to implement regular key rotation policies to mitigate the code injection attack.

  • Recommend that the development team incorporates input validation and parameterized queries into their coding standards to prevent similar vulnerabilities in future releases.

CompTIA PenTest+ PT0-002
Reporting and Communication
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot