
EC-CouncilCertified Cybersecurity Technician
Domain 3Objective 2
Application Security CCT Practice Questions (Page 8)
Part of the Security Assessment and Application Security domain, which makes up ~9% of our current practice bank.
51questions here
11free pages
10concepts
Questions 36–40
- 36
A company is deploying a web application to a cloud environment. The application stores sensitive data and must comply with a regulation that requires data to be encrypted at rest. The security team must choose a key management strategy. They want to minimize the risk of key compromise while maintaining the ability to revoke keys quickly if a breach occurs. Which approach is BEST?
Select an answer first - 37
A system administrator is deploying a new web application to a production server. The application stores sensitive customer data and uses a configuration file with database credentials. Which deployment practice is most secure?
Select an answer first - 38
Why is it important to consider application security early in the software development lifecycle (SDLC)?
Select an answer first - 39
A company uses a Web Application Firewall (WAF) to protect its web application. The WAF is currently blocking a legitimate user who is submitting a form with a text field that contains the string `' OR 1=1 --`. The user is a researcher entering a mathematical expression. The security team wants to allow this legitimate request while still blocking SQL injection attempts. What is the BEST approach?
Select an answer first - 40
A developer is fixing a cross-site scripting (XSS) vulnerability. The application reflects user input in a JavaScript context within an HTML page. Which encoding practice is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.