Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC GCCC Exam - Topic 2 Question 85 Discussion

What is a recommended defense for the CIS Control for Application Software Security?
C) Run a dedicated vulnerability scanner against backend databases
A) Keep debugging code in production web applications for quick troubleshooting
B) Limit access to the web application production environment to just the developers
D) Display system error messages for only non-kernel related events

GIAC GCCC Exam - Topic 2 Question 85 Discussion

Actual exam question for GIAC's GCCC exam
Question #: 85
Topic #: 2
[All GCCC Questions]

What is a recommended defense for the CIS Control for Application Software Security?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Kati
3 days ago
D helps prevent information leaks. It's a solid defense.
upvoted 0 times
...
Sylvia
8 days ago
C covers backend security well. Can't overlook vulnerabilities.
upvoted 0 times
...
Viola
13 days ago
B is too restrictive. Developers need access, but not too much.
upvoted 0 times
...
Vashti
19 days ago
A is risky. Debugging code in production? No way!
upvoted 0 times
...
Felicitas
24 days ago
I agree, but D seems important too. Hiding error messages is smart.
upvoted 0 times
...
Shalon
29 days ago
I think option C is the best choice. Vulnerability scanners are crucial.
upvoted 0 times
...
Catalina
1 month ago
B sounds good, but what if they need to troubleshoot?
upvoted 0 times
...
Golda
1 month ago
Wait, is it really okay to limit access just to developers? Seems risky.
upvoted 0 times
...
Vincent
1 month ago
D is crucial! No one wants to expose sensitive info.
upvoted 0 times
...
Annita
2 months ago
I disagree, A can lead to security risks if left in production.
upvoted 0 times
...
Donette
2 months ago
C is a solid choice! Vulnerability scanners are essential.
upvoted 0 times
...
Terina
2 months ago
I vaguely remember that keeping debugging code in production is a bad practice, but I can't remember why that would be relevant to this question.
upvoted 0 times
...
Refugia
4 months ago
I practiced a similar question on vulnerability scanning, and I think running a scanner is important, but it might not be the main defense for application security.
upvoted 0 times
...
Jacquelyne
4 months ago
I feel like displaying system error messages could lead to security risks, but I can't recall the exact details.
upvoted 0 times
...
Christiane
4 months ago
I think I remember something about limiting access to production environments, but I'm not sure if it's the best option here.
upvoted 0 times
...

Save Cancel