exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 131 discussion

Actual exam question from ISC's CISSP
Question #: 131
Topic #: 1
[All CISSP Questions]

Which of the following vulnerabilities can be BEST detected using automated analysis?

  • A. Multi-step process attack vulnerabilities
  • B. Business logic flaw vulnerabilities
  • C. Valid cross-site request forgery (CSRF) vulnerabilities
  • D. Typical source code vulnerabilities
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
InclusiveSTEAM
4 months, 2 weeks ago
D is the best answer. Typical source code vulnerabilities are best detected using automated analysis tools like static application security testing (SAST). A - Multi-step process attacks are complex and span business logic and workflows, difficult for automated tools to detect. B - Business logic flaws require understanding of application's intended behavior, hard to detect automatically. C - Valid CSRF tokens can look like false positives, automated tools may not determine legitimacy well. In contrast, typical code flaws like SQLi, XSS, insecure functions etc. are well detected by SAST which analyzes source code for known vulnerable patterns. Automated analysis excels at finding these typical vulnerabilities that have known signatures in code.
upvoted 2 times
...
Firedragon
1 year, 3 months ago
Selected Answer: D
D. https://www.techtarget.com/searchsecurity/definition/vulnerability-assessment-vulnerability-analysis Application scans test websites to detect known software vulnerabilities and incorrect configurations in network or web applications.
upvoted 2 times
jackdryan
10 months ago
D is correct
upvoted 1 times
...
...
dev46
1 year, 5 months ago
Selected Answer: D
D is correct
upvoted 4 times
CharlesL
1 year, 5 months ago
I know D is correct after clicking the button. :)
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago