Security & Error Handling Flashcards
6 cards from real CPP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Security & Error Handling flashcards as text
What is input validation and why is it critical for secure software?
Answer: Checking that user inputs match expected formats and ranges to prevent injection attacks and data corruption
Input validation rejects or sanitizes unexpected inputs at system boundaries, preventing SQL injection, XSS, and buffer overflow attacks.
What is the principle of least privilege in security?
Answer: Giving users and programs only the minimum access rights needed to perform their tasks
Least privilege minimizes the damage a compromised account or buggy code can do by limiting what resources it can access.
What is SQL injection?
Answer: An attack where malicious SQL code is inserted into input fields to manipulate the database
SQL injection exploits unsanitized user input concatenated directly into SQL queries, allowing attackers to read, modify, or delete data.
What is a try-catch-finally block used for?
Answer: Handling exceptions gracefully: try runs the code, catch handles exceptions, finally always runs for cleanup
Try-catch-finally provides structured exception handling: catching errors to prevent crashes and using finally to ensure resources are always released.
What is Cross-Site Scripting (XSS)?
Answer: An attack where malicious scripts are injected into web pages viewed by other users
XSS injects malicious client-side scripts into pages, allowing attackers to steal cookies, session tokens, or redirect users.
What is defensive programming?
Answer: Writing code that anticipates and handles invalid inputs, unexpected states, and failures gracefully
Defensive programming assumes that inputs may be invalid and external systems may fail, adding validation and error handling proactively.