โ† All CCP Flashcard Decks

Application Security & Secure Coding Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Application Security & Secure Coding flashcards as text
  1. Which OWASP Top 10 vulnerability occurs when an attacker inserts malicious SQL code into an input field that is directly passed to a database query?

    Answer: SQL Injection

    SQL Injection occurs when untrusted data is sent to an interpreter as part of a command or query, allowing attackers to manipulate database queries.

  2. What is the primary purpose of input validation in secure application development?

    Answer: To ensure data conforms to expected format before processing

    Input validation ensures that only properly formed data enters a system, preventing malformed data from causing unexpected behavior or enabling attacks.

  3. A developer stores session tokens in a URL query string. Which security risk does this practice introduce?

    Answer: Session token exposure via browser history and server logs

    Session tokens in URLs can be logged in browser history, server access logs, and referrer headers, exposing them to unauthorized parties.

  4. Which type of Cross-Site Scripting (XSS) attack stores malicious script on the server to be served to all subsequent visitors?

    Answer: Stored XSS

    Stored (Persistent) XSS saves malicious scripts in the server's database, which are then delivered to every user who views the affected page.

  5. In the Secure Software Development Lifecycle (SSDLC), during which phase should threat modeling primarily be performed?

    Answer: Design

    Threat modeling is most effective during the Design phase, enabling architects to identify and mitigate security risks before code is written.

  6. A buffer overflow vulnerability is best mitigated through which secure coding technique?

    Answer: Applying bounds checking and safe string functions

    Bounds checking and the use of safe string-handling functions (e.g., strncpy instead of strcpy) prevent data from overflowing allocated memory buffers.

  7. Which HTTP security header helps prevent Cross-Site Scripting attacks by specifying which dynamic resources are allowed to load?

    Answer: Content-Security-Policy

    Content-Security-Policy (CSP) instructs browsers to only execute or render resources from trusted sources, significantly reducing XSS attack surface.