CompTIA
PT0-002 · Question #309
A penetration tester uncovered a flaw in an online banking web application that allows arbitrary requests to other internal network assets through a server-side request forgery. Which of the following
Sign in or unlock PT0-002 to reveal the answer and full explanation for question #309. The question stem and answer options stay visible for context.
Attacks and Exploits
Question
A penetration tester uncovered a flaw in an online banking web application that allows arbitrary requests to other internal network assets through a server-side request forgery. Which of the following would BEST reduce the risk of attack?
Options
- AImplement multifactor authentication on the web application to prevent unauthorized access of the
- BConfigure a secret management solution to ensure attackers are not able to gain access to
- CEnsure a patch management system is in place to ensure the web server system is hardened.
- DSanitize and validate all input within the web application to prevent internal resources from being
- EEnsure that enhanced logging is enabled on the web application to detect the attack.
Unlock PT0-002 to see the answer
You've previewed enough free PT0-002 questions. Unlock PT0-002 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Server-Side Request Forgery (SSRF)#Input Validation#Web Application Security#Vulnerability Mitigation