Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GCCC Topic 4 Question 38 Discussion

Actual exam question for GIAC's GCCC exam
Question #: 38
Topic #: 4
[All GCCC Questions]

What is a recommended defense for the CIS Control for Application Software Security?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

Jessenia
1 months ago
C is the clear winner here. Scanning the databases for vulnerabilities is a must-have for application security. Unless, of course, you want your data served up on a silver platter to hackers.
upvoted 0 times
...
Selma
1 months ago
A is so bad, it's almost comical. Leaving debugging code in production? That's like leaving the front door wide open and expecting no one to break in.
upvoted 0 times
Jaime
3 days ago
B) Limit access to the web application production environment to just the developers
upvoted 0 times
...
...
Timothy
1 months ago
I'm going with D. Showing error messages for non-kernel events will give attackers a lot of juicy information to work with. Wait, is that a trick question?
upvoted 0 times
...
Geoffrey
1 months ago
B sounds tempting, but limiting access to just developers isn't enough. We need to secure the application itself, which is why C is the way to go.
upvoted 0 times
Magdalene
18 days ago
B sounds tempting, but limiting access to just developers isn't enough.
upvoted 0 times
...
...
Rikki
2 months ago
I think running a dedicated vulnerability scanner against backend databases could also help in securing the application software.
upvoted 0 times
...
Hubert
2 months ago
Definitely not A. Keeping debugging code in production is a big no-no for security. The correct answer has to be C - running a vulnerability scanner on the backend databases.
upvoted 0 times
Luz
28 days ago
Yes, C - running a dedicated vulnerability scanner against backend databases is the correct answer.
upvoted 0 times
...
Luz
1 months ago
I agree, A is definitely not the recommended defense for application software security.
upvoted 0 times
...
Jarod
1 months ago
Yes, C - running a dedicated vulnerability scanner against backend databases is the correct answer.
upvoted 0 times
...
Jarod
2 months ago
I agree, A is definitely not the recommended defense for application software security.
upvoted 0 times
...
...
Omer
3 months ago
I agree with Omega. It's important to restrict access to prevent unauthorized changes.
upvoted 0 times
...
Omega
3 months ago
I think the recommended defense is to limit access to the web application production environment to just the developers.
upvoted 0 times
...

Save Cancel