exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 305 discussion

Actual exam question from CompTIA's SY0-601
Question #: 305
Topic #: 1
[All SY0-601 Questions]

Which of the following would be used to find the MOST common web-application vulnerabilities?

  • A. OWASP
  • B. MITRE ATT&CK
  • C. Cyber Kill Chain
  • D. SDLC
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sauna28
Highly Voted 2 years, 4 months ago
Selected Answer: A
Anything related to WEB APPLICATION SECURITY = OWASP The Open Web Application Security Project (FRAMEWORK) is an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. The Open Web Application Security Project provides free and open resources. • MITRE’s Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK™) is a curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target. ATT&CK is useful for understanding security risk against known adversary behavior, for planning security improvements, and verifying defenses work as expected.
upvoted 19 times
...
FMMIR
Highly Voted 2 years, 4 months ago
Selected Answer: A
The correct answer is A. OWASP (Open Web Application Security Project). OWASP is a non-profit organization that provides a comprehensive list of the most common web application vulnerabilities and offers recommendations for addressing them. MITRE ATT&CK is a framework for tracking and analyzing the tactics, techniques, and procedures used by attackers, while Cyber Kill Chain is a methodology for identifying and disrupting an attacker's activities. SDLC (Software Development Life Cycle) is a systematic approach to developing software.
upvoted 7 times
...
ApplebeesWaiter1122
Most Recent 1 year, 10 months ago
Selected Answer: A
OWASP is a widely recognized organization that provides resources, tools, and guidelines for web application security. The OWASP Top Ten is a list of the most critical web application security risks, which includes common vulnerabilities such as injection attacks, cross-site scripting (XSS), and insecure direct object references. By consulting the OWASP resources, developers and security professionals can identify and mitigate these common vulnerabilities in web applications.
upvoted 6 times
...
Blueteam
2 years, 4 months ago
A is the most specific answer.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago