exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 84 discussion

Actual exam question from ISC's CCSP
Question #: 84
Topic #: 1
[All CCSP Questions]

Which of the following threat types involves an application developer leaving references to internal information and configurations in code that is exposed to the client?

  • A. Sensitive data exposure
  • B. Security misconfiguration
  • C. Insecure direct object references
  • D. Unvalidated redirect and forwards
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MaciekMT
1 month ago
Selected Answer: C
from AI: Insecure direct object references (IDOR) is a threat type that occurs when an application developer leaves references to internal information in code that is exposed to the client. Explanation IDOR A vulnerability that occurs when an application provides direct access to objects based on user-supplied input. This can happen when an application uses an identifier to access an object in a database without checking for access control or authentication. Attackers Attackers can use IDOR to bypass authorization and access resources in the system directly, such as database records or files. Causes IDOR can occur due to missing access control checks, which fail to verify whether a user should be allowed to access specific data.
upvoted 1 times
...
Pika26
3 months ago
Selected Answer: C
C. Insecure direct object references
upvoted 1 times
...
xroxro
1 year ago
Question not precise enough to clearly choose between A and C. A if data is generic data (for example, version of the internal database) C if used by a backend application (for example internal authentication token)
upvoted 3 times
...
akg001
1 year, 3 months ago
Selected Answer: C
C. Insecure direct object references
upvoted 2 times
...
certifiedgeek
1 year, 3 months ago
This question can also lean forward with "sensitive information disclosure".
upvoted 2 times
DarkHorse99
1 year, 1 month ago
true but no need to add confusion
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago