DevNet Associate (DEVASC) v1.0Application Deployment and SecurityMedium
A developer is designing an API that will be accessed by both internal and external clients. To protect against common web vulnerabilities, they decide to implement input validation for all incoming requests. Which security best practice does this directly address?
- ASecurity by Obscurity
- BLeast Privilege Principle
- CSecure Coding Practices
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: C. Secure Coding Practices
Input validation is a fundamental secure coding practice that helps prevent various attacks like SQL injection, cross-site scripting (XSS), and command injection by ensuring that all data received by the application conforms to expected formats and values.
Why the other options are wrong
- A. Security by Obscurity relies on hiding information, which is not a robust security measure and unrelated to input validation.
- B. Least Privilege Principle relates to granting minimum necessary permissions, not input validation.
- D. Defense in Depth is a strategy of multiple security layers, while input validation is a specific practice.
Secure Coding Practices
A set of guidelines and techniques used by developers to write code that is resistant to security vulnerabilities. This includes practices like input validation, proper error handling, and secure API usage.
- Prevents common vulnerabilities (e.g., SQLi, XSS).
- Includes input validation, output encoding, error handling.
- Aims to build security into the application from the start.
Memory trick: Secure code validates, least privilege restricts, defense in depth layers.