CompTIA Project+ (PK0-005)Basics of IT and GovernanceMedium

A project involves deploying a new public-facing web application. During the security considerations phase, the team identifies that the application will handle user authentication and sensitive data submission. To protect against common web vulnerabilities, which security measure should be a primary focus during development?

  1. ARegularly patching operating systems and underlying infrastructure.
  2. BEnsuring all project team members have strong, unique passwords.
  3. CImplementing input validation and protection against SQL injection and XSS.
  4. DImplementing robust physical security for the data center servers.
Show answer & explanation

Correct answer: C. Implementing input validation and protection against SQL injection and XSS.

The scenario specifies a 'public-facing web application' handling 'user authentication and sensitive data submission.' SQL injection and Cross-Site Scripting (XSS) are common web application vulnerabilities that directly target input fields and user interactions, making robust input validation and specific protections against these attacks critical for application security.

Why the other options are wrong

  • A. OS patching is crucial for infrastructure security but doesn't directly prevent application-level vulnerabilities like those mentioned.
  • B. Strong passwords for team members are good practice but don't protect the application itself from external web attacks.
  • D. Physical security is important but doesn't protect against application-layer attacks like SQL injection or XSS.

Web Application Vulnerabilities

Weaknesses in web applications that attackers can exploit to gain unauthorized access, steal data, or disrupt services.

  • Common examples include SQL Injection, Cross-Site Scripting (XSS), Broken Authentication.
  • Often result from improper input validation or insecure coding practices.
  • OWASP Top 10 lists the most critical web application security risks.

Memory trick: Web App Security: Validate Input, Protect Data, Authenticate Users.

More Basics of IT and Governance questions