Free CompTIA PenTest+ PT0-002 Practice Question

During a penetration testing engagement, your team has identified an application that is vulnerable to command injection due to insufficient input validation. In your final report, what is the most appropriate process-level remediation recommendation to address this specific vulnerability?

  • Recommend the implementation of proper input sanitization and the use of prepared statements or parameterized queries.

  • Suggest increasing the complexity of input validation rules within the application code.

  • Advise the client to update their application frameworks to the latest versions to avoid command injection.

  • Instruct the client to configure the existing Web Application Firewall (WAF) to block command injection attacks.

This question's topic:
CompTIA PenTest+ PT0-002 / 
Reporting and Communication
Your Score:

Check or uncheck an objective to set which questions you will receive.