Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam CAP All Questions
Exam CAP All Questions

View all questions & answers for the CAP exam

The SecOps Group AppSec Practitioner CAP Question # 1 Topic 1 Discussion

CAP Exam Topic 1 Question 1 Discussion:
Question #: 1
Topic #: 1

After purchasing an item on an e-commerce website, a user can view his order details by visiting the URL:

https://example.com/order_id=53870

A security researcher pointed out that by manipulating the order_id value in the URL, a user can view arbitrary orders and sensitive information associated with that order_id.

Which of the following is correct?


A.

The root cause of the problem is a lack of input validation and by implementing a strong whitelisting, the problem can be solved


B.

The root cause of the problem is a weak authorization (Session Management) and by validating a user's privileges, the issue can be fixed


C.

The problem can be solved by implementing a Web Application Firewall (WAF)


D.

None of the above


Get Premium CAP Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.