Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A company is developing a new mobile application that will handle sensitive user data. Before deployment, the security team conducts a thorough review, including code analysis and penetration testing, to identify and fix any weaknesses that an attacker could exploit. What type of security threat are they primarily trying to prevent by performing these actions?
- APhysical Security Breaches
- BSocial Engineering
- CInsider Threats
- DApplication Vulnerabilities
Show answer & explanationAnswer & explanation
Correct answer: D. Application Vulnerabilities
Code analysis and penetration testing are methods specifically designed to discover flaws and weaknesses within software applications. These weaknesses, if exploited, are known as application vulnerabilities. The team's actions directly aim to prevent these.
Why the other options are wrong
- A. Physical Security Breaches involve unauthorized access to physical premises or hardware.
- B. Social Engineering exploits human psychology, not software code.
- C. Insider Threats come from within the organization, often through authorized access, not necessarily code flaws.
Application Vulnerabilities
Weaknesses or flaws within software applications that can be exploited by attackers to gain unauthorized access, cause denial of service, or compromise data.
- Can exist in code, design, or configuration.
- Often identified through code review, penetration testing, and vulnerability scanning.
- Examples include SQL injection, XSS, broken authentication.
Memory trick: Threats: Apps, Humans, Networks, Physical