{"id":19308,"date":"2026-09-23T04:50:33","date_gmt":"2026-09-23T04:50:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=19308"},"modified":"2026-09-23T04:50:33","modified_gmt":"2026-09-23T04:50:33","slug":"isc-csslp-practice-test-questions-and-exam-dumps-part3-q41-60","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-csslp-practice-test-questions-and-exam-dumps-part3-q41-60\/","title":{"rendered":"ISC CSSLP Practice Test Questions and Exam Dumps Part3 Q41-60"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/csslp-exam-dumps\"><b>ISC CSSLP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 41.<\/b><\/p>\n<p><b>A development team is defining security requirements for a new customer portal. Which requirement is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The application should be secure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitive customer data must be encrypted in transit and at rest using approved mechanisms<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Developers should use good coding practices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The system should avoid vulnerabilities<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Sensitive customer data must be encrypted in transit and at rest using approved mechanisms<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security requirements should be specific, measurable, and testable. A requirement that defines what data must be protected and under what conditions can be traced to design controls and verified during testing. Vague statements such as \u201cthe application should be secure\u201d do not provide enough information for developers or testers to determine whether the requirement has been satisfied.<\/span><\/p>\n<p><b>Question 42.<\/b><\/p>\n<p><b>Which practice BEST helps prevent path traversal vulnerabilities in file-access functionality?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Validate and canonicalize paths, restrict access to approved directories, and avoid direct use of untrusted filenames<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase file-system capacity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow users to specify absolute server paths<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Validate and canonicalize paths, restrict access to approved directories, and avoid direct use of untrusted filenames<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Path traversal occurs when attackers manipulate file paths to access files outside intended directories. Applications should canonicalize and validate paths, use allowlisted locations, generate server-side filenames where possible, and restrict the process account to only required directories. User-supplied path values should never be trusted directly. Least privilege further limits the impact if validation fails.<\/span><\/p>\n<p><b>Question 43.<\/b><\/p>\n<p><b>A security architect wants to understand how an attacker might move from a public web interface to a sensitive backend system. Which activity is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Usability testing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Performance benchmarking<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Attack-path and threat-model analysis<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Database indexing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Attack-path and threat-model analysis<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling helps teams examine how an attacker might cross trust boundaries, exploit exposed interfaces, abuse privileges, or pivot between components. Mapping attack paths from public entry points to sensitive assets can reveal missing controls such as segmentation, authorization, input validation, or monitoring. Performance and usability testing do not directly evaluate attacker behavior.<\/span><\/p>\n<p><b>Question 44.<\/b><\/p>\n<p><b>A software application uses a third-party authentication library that is no longer maintained. What is the BEST response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep using it indefinitely because it currently works<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable authentication monitoring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore future vulnerabilities in the library<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assess the risk and plan migration to a supported alternative<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Assess the risk and plan migration to a supported alternative<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unsupported security components are risky because newly discovered vulnerabilities may never receive fixes. The organization should evaluate current exposure, identify compensating controls if necessary, and plan migration to a maintained library. Security-critical dependencies should be tracked throughout the software lifecycle so end-of-support events do not become unexpected production risks.<\/span><\/p>\n<p><b>Question 45.<\/b><\/p>\n<p><b>Which principle BEST supports checking authorization whenever a protected resource is requested?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Complete mediation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Open design<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Economy of mechanism<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Complete mediation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Complete mediation requires that every access attempt to a protected resource be checked against applicable authorization policy. A prior successful access should not automatically authorize later requests because permissions or context may have changed. This principle is especially relevant to APIs, object access, and privileged functions where inconsistent checks can lead to authorization bypass.<\/span><\/p>\n<p><b>Question 46.<\/b><\/p>\n<p><b>A development team needs to store user passwords. Which approach is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypt passwords with a reversible shared key<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use a strong adaptive password-hashing function with unique salts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store passwords in plaintext in a protected database<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encode passwords using Base64<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use a strong adaptive password-hashing function with unique salts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passwords generally should not be stored in recoverable form. Adaptive password-hashing functions are designed to make offline guessing attacks computationally expensive, while unique salts prevent identical passwords from producing identical stored values and reduce the effectiveness of precomputed attacks. Plaintext storage, reversible encryption, and simple encoding provide weaker protection if the credential database is compromised.<\/span><\/p>\n<p><b>Question 47.<\/b><\/p>\n<p><b>A security review finds that an API returns more customer information than the requesting application actually needs. Which principle is MOST directly relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Fail secure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Separation of duties<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> High availability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Data minimization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization means collecting, processing, and disclosing only the information necessary for the intended purpose. Returning unnecessary customer attributes increases privacy exposure and breach impact without adding business value. APIs should therefore provide only required fields and enforce authorization at an appropriate level. Minimization can also simplify compliance and reduce downstream security obligations.<\/span><\/p>\n<p><b>Question 48.<\/b><\/p>\n<p><b>A release pipeline permits developers to bypass testing and deploy directly to production. What is the BEST improvement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase developer privileges<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable deployment logging<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use one shared production account<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require controlled deployment gates with testing, approval, and auditability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Require controlled deployment gates with testing, approval, and auditability<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secure release process should prevent unreviewed code from reaching production. Deployment gates can enforce automated testing, security checks, approvals, artifact integrity verification, and traceability. Emergency paths may exist, but they should still preserve authorization and logging. Direct deployment by developers increases the risk of accidental, malicious, or untested changes reaching production systems.<\/span><\/p>\n<p><b>Question 49.<\/b><\/p>\n<p><b>Which activity BEST supports secure software requirements traceability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Linking each security requirement to design controls, implementation, and verification evidence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Recording only the final test results<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Documenting only functional requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing outdated requirements without review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Linking each security requirement to design controls, implementation, and verification evidence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traceability helps ensure that each requirement is addressed throughout the lifecycle. A requirement should map to architecture or design decisions, implementation mechanisms, and test evidence showing that it works as intended. This makes gaps easier to identify and supports audits, change impact analysis, and maintenance. Traceability also prevents security requirements from being lost as the software evolves.<\/span><\/p>\n<p><b>Question 50.<\/b><\/p>\n<p><b>A web application uses a random anti-forgery token for state-changing requests. Which attack is this control primarily intended to reduce?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> SQL injection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cross-site request forgery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Buffer overflow<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Path traversal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Cross-site request forgery<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-site request forgery tricks an authenticated user&#8217;s browser into sending an unwanted request to an application. Anti-forgery tokens help the server verify that a state-changing request originated from an expected application context rather than a malicious external page. SameSite cookie attributes, reauthentication for sensitive actions, and proper request validation can provide additional protection depending on the application&#8217;s architecture.<\/span><\/p>\n<p><b>Question 51.<\/b><\/p>\n<p><b>A security test shows that an application trusts a user-supplied role value sent from the browser. What is the MAIN weakness?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Insufficient encryption<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Excessive logging<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Authorization decisions are relying on untrusted client-side data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weak availability design<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Authorization decisions are relying on untrusted client-side data<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Client-controlled values can be modified by an attacker and should not be trusted for authorization. Roles, privileges, and access decisions should be derived from trusted server-side identity or policy information. Client-side values may be useful for display purposes, but the server must independently verify permissions before performing protected actions. Otherwise, attackers may escalate privilege simply by modifying request parameters.<\/span><\/p>\n<p><b>Question 52.<\/b><\/p>\n<p><b>Which approach BEST protects sensitive configuration secrets in a CI\/CD environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Place secrets directly in build scripts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store secrets in source repositories<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Share a single permanent token among all projects<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use a protected secrets service with scoped, auditable access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use a protected secrets service with scoped, auditable access<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CI\/CD pipelines frequently need credentials for repositories, artifact stores, deployment targets, or cloud services. These secrets should be stored in a dedicated secrets-management mechanism rather than source code or build scripts. Access should be narrowly scoped, auditable, and preferably short-lived. The pipeline itself should be treated as sensitive infrastructure because compromise can affect many downstream systems.<\/span><\/p>\n<p><b>Question 53.<\/b><\/p>\n<p><b>What is the PRIMARY purpose of dynamic application security testing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identify security weaknesses by interacting with a running application<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace secure coding standards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analyze source code without execution<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Measure developer productivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Identify security weaknesses by interacting with a running application<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic application security testing evaluates a running application from the outside or through exposed interfaces. It can identify issues such as input-validation flaws, authentication weaknesses, configuration problems, and some forms of injection. Because it observes application behavior during execution, it complements static analysis and code review. No single testing method should be relied upon to find every vulnerability.<\/span><\/p>\n<p><b>Question 54.<\/b><\/p>\n<p><b>A software team wants to reduce the risk that users remain authenticated after leaving a shared workstation unattended. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase session lifetime<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use appropriate idle timeouts and require reauthentication for sensitive actions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store session tokens permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable logout functionality<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use appropriate idle timeouts and require reauthentication for sensitive actions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Idle session timeouts reduce the period during which an unattended authenticated session can be misused. High-risk actions may also require reauthentication or step-up verification even within an active session. Timeout values should balance usability with the sensitivity of the application and operating environment. Sessions should also be invalidated properly when users log out or credentials are revoked.<\/span><\/p>\n<p><b>Question 55.<\/b><\/p>\n<p><b>Why should security teams verify the provenance of third-party software packages?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine whether the package has the shortest name<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To improve user-interface performance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To gain confidence that the component originated from an expected and trustworthy source<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate the need for vulnerability scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To gain confidence that the component originated from an expected and trustworthy source<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Software provenance helps establish where a component came from and whether it passed through an approved build or distribution process. This can reduce the risk of dependency substitution, repository compromise, or tampered packages. Provenance should be combined with integrity verification, vulnerability monitoring, approved repositories, and lifecycle management. It does not replace other software-supply-chain controls.<\/span><\/p>\n<p><b>Question 56.<\/b><\/p>\n<p><b>A team discovers that its error handler reveals stack traces and internal database queries to users. What is the BEST correction?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Display even more debugging detail<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all diagnostic information permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Send passwords with every error report<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Return generic user-facing errors and record detailed diagnostics in protected logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Return generic user-facing errors and record detailed diagnostics in protected logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detailed technical errors can reveal implementation details useful to attackers, including file paths, libraries, queries, and internal logic. Users generally need only enough information to understand that a request failed. Detailed diagnostics should be captured securely for authorized troubleshooting, with sensitive information excluded or masked. This approach preserves operational visibility without unnecessarily disclosing internal details.<\/span><\/p>\n<p><b>Question 57.<\/b><\/p>\n<p><b>What is the MAIN purpose of fuzz testing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Discover unexpected behavior by supplying malformed, random, or boundary-case inputs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace all functional testing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Measure network throughput<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create user documentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Discover unexpected behavior by supplying malformed, random, or boundary-case inputs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fuzz testing exercises software with unusual, malformed, or unexpected inputs to uncover crashes, memory errors, validation weaknesses, parsing problems, and other defects. It is particularly useful for parsers, protocols, file formats, and input-heavy interfaces. Fuzzing complements code review, static analysis, and conventional testing because it can expose behaviors developers did not explicitly anticipate.<\/span><\/p>\n<p><b>Question 58.<\/b><\/p>\n<p><b>A software team must securely compare authentication tokens. Which implementation concern is MOST relevant when protecting against timing attacks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use longer variable names<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use comparison routines designed to avoid data-dependent timing differences<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable authentication logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Convert tokens to uppercase first<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use comparison routines designed to avoid data-dependent timing differences<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Some naive comparison functions return as soon as they encounter the first difference. This can create measurable timing variations that may leak information about secret values. Security-sensitive token, MAC, or signature comparisons should use constant-time or otherwise timing-resistant routines provided by trusted libraries when appropriate. Developers should avoid inventing custom cryptographic comparison logic.<\/span><\/p>\n<p><b>Question 59.<\/b><\/p>\n<p><b>A vulnerability is fixed in one branch of a software product but remains in other supported versions. What should the security team do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume all versions are fixed automatically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Close the issue after the first patch<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identify all affected supported versions and ensure each is remediated or otherwise addressed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stop tracking the vulnerability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Identify all affected supported versions and ensure each is remediated or otherwise addressed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security defects can affect multiple maintained versions of a product. Remediating one branch does not automatically protect others. The organization should determine affected releases, provide patches or mitigations where required, communicate appropriately, and verify that fixes are applied consistently. Vulnerability management should account for the complete supported product lifecycle rather than a single development branch.<\/span><\/p>\n<p><b>Question 60.<\/b><\/p>\n<p><b>Which practice BEST reflects mature secure software maintenance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stop security testing after release<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore vulnerabilities in third-party dependencies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Patch only after successful exploitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Continuously monitor vulnerabilities, dependencies, configuration, and changing threats throughout support<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Continuously monitor vulnerabilities, dependencies, configuration, and changing threats throughout support<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Software security responsibilities continue after deployment. New vulnerabilities may be discovered in application code, third-party components, platforms, and infrastructure. Mature maintenance includes monitoring advisories, assessing exposure, patching or mitigating issues, verifying fixes, and reassessing security assumptions as threats and requirements change. Secure software remains actively managed until it is formally retired.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CSSLP Exam Dumps and Practice Test Dumps &nbsp; Question 41. A development team is defining security requirements for a new customer portal. Which requirement is MOST appropriate? The application should be secure Sensitive customer data must be encrypted in transit and at rest using approved mechanisms Developers should use good coding practices [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19308"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=19308"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19308\/revisions"}],"predecessor-version":[{"id":19309,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19308\/revisions\/19309"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=19308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=19308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=19308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}