Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Shared Assessments CTPRP Exam - Topic 2 Question 4 Discussion

Which statement is NOT a method of securing web applications?
C) Adhere to web content accessibility guidelines
A) Ensure appropriate logging and review of access and events
B) Conduct periodic penetration tests
D) Include validation checks in SDLC for cross site scripting and SOL injections

Shared Assessments CTPRP Exam - Topic 2 Question 4 Discussion

Actual exam question for Shared Assessments's CTPRP exam
Question #: 4
Topic #: 2
[All CTPRP Questions]

Which statement is NOT a method of securing web applications?

Show Suggested Answer Hide Answer
Suggested Answer: C

Web content accessibility guidelines (WCAG) are a set of standards that aim to make web content more accessible to people with disabilities, such as visual, auditory, cognitive, or motor impairments. While WCAG is a good practice for web development and usability, it is not directly related to web application security. WCAG does not address the common security risks that web applications face, such as injection, broken authentication, misconfiguration, or vulnerable components. Therefore, adhering to WCAG is not a method of securing web applications, unlike the other options.Reference:

4: OWASP Top 10, a standard awareness document for web application security, lists the most critical security risks to web applications and provides best practices to prevent or mitigate them.

5: SANS Institute, a leading provider of cybersecurity training and certification, offers a security checklist for web application technologies (SWAT) that covers best practices for error handling, data protection, configuration, authentication, session management, input and output handling, and access control.

6: Built In, a platform for tech professionals, provides 13 web application security best practices, such as using a web application firewall, keeping track of APIs, enforcing expected application behaviors, and following the OWASP Top 10.


Contribute your Thoughts:

0/2000 characters
Mammie
22 days ago
Logging and penetration tests are crucial!
upvoted 0 times
...
Rozella
27 days ago
Wait, are we sure about that?
upvoted 0 times
...
Teddy
1 month ago
Totally agree, C is more about accessibility.
upvoted 0 times
...
Lisha
1 month ago
C is not about security.
upvoted 0 times
...
Susana
1 month ago
I could be wrong, but I think C is the odd one out here. It doesn't seem to focus on security like the others do.
upvoted 0 times
...
Tenesha
2 months ago
I practiced a similar question where we had to identify security measures, and I think B is definitely a method since penetration tests are crucial.
upvoted 0 times
...
Chauncey
2 months ago
I'm not entirely sure, but I feel like C might not directly relate to security. It seems more about accessibility than protection.
upvoted 0 times
...
Nana
2 months ago
I remember studying about logging and access reviews, so I think A is definitely a method of securing web applications.
upvoted 0 times
...
Alesia
2 months ago
I could be wrong, but I think C is the odd one out here. It doesn't seem to focus on security like the others do.
upvoted 0 times
...
Launa
2 months ago
I practiced a similar question where we had to identify security measures, and I think B is definitely a method since penetration tests are crucial.
upvoted 0 times
...
Glenna
2 months ago
I'm not entirely sure, but I feel like C might not directly relate to security. It seems more about accessibility than protection.
upvoted 0 times
...
Dona
3 months ago
I remember studying about logging and access reviews, so I think A is definitely a method of securing web applications.
upvoted 0 times
...

Save Cancel