Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A company is developing a new mobile application that will handle sensitive user data. Before deployment, they conduct thorough penetration testing and code reviews to identify and remediate vulnerabilities. This proactive approach primarily aims to address which common security threat category?

  1. ADenial of Service (DoS)
  2. BApplication Vulnerabilities
  3. CMalware
  4. DSocial Engineering
Show answer & explanation

Correct answer: B. Application Vulnerabilities

Penetration testing and code reviews are designed to find flaws (vulnerabilities) within the application itself. Addressing these before deployment directly mitigates threats arising from application vulnerabilities.

Why the other options are wrong

  • A. DoS attacks aim to make a service unavailable, which is a different threat than exploitable code flaws.
  • C. Malware is malicious software, but the primary goal here is to fix inherent flaws in the company's own application.
  • D. Social engineering exploits human psychology, not software flaws found by code review.

Application Vulnerabilities

Weaknesses or flaws in software applications that can be exploited by attackers to compromise security.

  • Can be found in custom code or third-party libraries.
  • Common examples include SQL injection, XSS, broken authentication.
  • Mitigated by secure coding practices, testing, and patching.

Memory trick: Threats: Malware lurks, Phishing tricks, Vulnerabilities wait.

More Security Principles questions