Google Professional Cloud Security Engineer Exam - Topic 1 Question 101 Discussion
You are on your company's development team. You noticed that your web application hosted in staging on GKE dynamically includes user data in web pages without first properly validating the inputted data. This could allow an attacker to execute gibberish commands and display arbitrary content in a victim user's browser in a production environment.How should you prevent and fix this vulnerability?
D) Use Web Security Scanner in staging to simulate an XSS injection attack, and then use a templating system that supports contextual auto-escaping.
A) Use Cloud IAP based on IP address or end-user device attributes to prevent and fix the vulnerability.
B) Set up an HTTPS load balancer, and then use Cloud Armor for the production environment to prevent the potential XSS attack.
C) Use Web Security Scanner to validate the usage of an outdated library in the code, and then use a secured version of the included library.
Billye
9 months agoGladys
9 months agoAilene
9 months agoSvetlana
9 months agoPansy
9 months agoStaci
10 months agoLoren
10 months agoLezlie
10 months agoMaile
10 months agoBenton
11 months agoCristal
11 months agoMelodie
11 months agoSunshine
11 months agoAn
1 year agoOretha
1 year agoJules
1 year agoPearlie
1 year agoMicheal
1 year agoJennie
1 year agoJose
1 year agoShaunna
1 year agoValentin
1 year agoRonna
1 year agoTegan
1 year agoStarr
1 year agoAlyssa
1 year agoTonja
1 year agoAlease
1 year agoSusana
1 year agoRueben
1 year agoHuey
1 year agoAbel
1 year agoSuzi
1 year ago