Arcitura Education S90.19 Exam - Topic 3 Question 16 Discussion
Service A, residing outside the private network of an organization, provides logic that sanitizes message error information on behalf of other services that reside inside the private network, behind a firewall. Where is the vulnerability in this architecture?
B) The sanitization logic resides outside the private network. Therefore, if communication between Service A and the services within the private network is compromised, an attacker can get access to sensitive data from non-sanitized messages generated by services inside the private network.
A) There is no central management of error messages. Instead, policy enforcement points should be used so that all services are required to comply with a policy that states that any error message generated needs to be free of sensitive data.
C) There is no single sign-on mechanism in place, which puts all services (within and outside the private network) at risk.
Regenia
7 months agoCherilyn
7 months agoWynell
8 months agoCarmen
8 months agoGertude
8 months agoElli
8 months agoYaeko
8 months ago