Free CompTIA PenTest+ PT0-002 Practice Question

During a penetration testing engagement, you have identified that a client's web application is vulnerable to code injection attacks due to the lack of input validation. Which recommendation would best align with integrating security practices into the client's software development life cycle?

  • Recommend that the development team incorporates input validation and parameterized queries into their coding standards to prevent similar vulnerabilities in future releases.

  • Urge the client to enforce mandatory staff vacations to reduce the risk of insider threats which may lead to code injection vulnerabilities.

  • Suggest the implementation of better certificate management practices to secure the web application against code injection.

  • Advise the client to implement regular key rotation policies to mitigate the code injection attack.

  • Propose the addition of more comprehensive user training programs to prevent code injection attacks.

This question's topic:
CompTIA PenTest+ PT0-002 / 
Reporting and Communication
Your Score:

Check or uncheck an objective to set which questions you will receive.