CCT Application Security & Secure Coding Flashcards
6 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCT Application Security & Secure Coding flashcards as text
Which phase of the Software Development Lifecycle (SDLC) is the most cost-effective time to identify and fix security vulnerabilities?
Answer: Requirements and design phase
Fixing security flaws during the requirements and design phase is exponentially cheaper than addressing them after deployment, following the 'shift-left' security principle.
What is the purpose of Static Application Security Testing (SAST)?
Answer: Analyzing source code for security flaws without executing it
SAST tools analyze source code, bytecode, or binaries for security vulnerabilities without executing the program, enabling early detection during development.
What type of vulnerability does a race condition in application code typically lead to?
Answer: Time-of-check to time-of-use (TOCTOU) attack
Race conditions can lead to TOCTOU vulnerabilities, where an attacker manipulates a resource between the time it is checked and the time it is used.
What is the recommended way to store user passwords in an application database?
Answer: Hashed using a strong adaptive algorithm like bcrypt or Argon2
Adaptive hashing algorithms like bcrypt or Argon2 incorporate salting and are computationally expensive, making brute-force and rainbow table attacks impractical.
What is insecure direct object reference (IDOR)?
Answer: Exposing internal implementation objects to users without proper authorization checks
IDOR occurs when an application uses user-controllable input to access objects directly without verifying the user has authorization for that specific object.
Which HTTP security header prevents the browser from interpreting files as a different MIME type than declared?
Answer: X-Content-Type-Options
The `X-Content-Type-Options: nosniff` header instructs browsers not to perform MIME type sniffing, preventing attacks that rely on uploading files disguised with incorrect MIME types.