
EC-CouncilCertified Cybersecurity Technician
Domain 3Objective 2
Application Security CCT Practice Questions (Page 10)
Part of the Security Assessment and Application Security domain, which makes up ~9% of our current practice bank.
51questions here
11free pages
10concepts
Questions 46–50
- 46
A company stores customer payment card data in a database. The security team wants to ensure that even if the database is compromised, the data is unreadable. Which control is most effective?
Select an answer first - 47
What is a key characteristic of Static Application Security Testing (SAST)?
Select an answer first - 48
A development team is fixing a critical vulnerability in a web application where user-supplied search terms are concatenated directly into SQL queries. The team wants a solution that addresses the root cause without requiring changes to the database schema. Which approach should they implement?
Select an answer first - 49
A developer is writing a web form that accepts user comments and displays them on a public page. The application previously suffered a stored XSS attack. Which secure coding practice should be applied to prevent recurrence?
Select an answer first - 50
What is the primary difference between authentication and authorization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.