Testing
Finals Assessment Review
(Questions & Solutions)
2025
©2025
, Q1. Which of the following security testing approaches is most
effective for simulating a real-world attacker’s behavior against a web
application?
A. Static code analysis
B. Penetration testing
C. Unit testing
D. Regression testing
ANS: B (Penetration testing)
Rationale: Penetration testing involves simulating real attacks to
exploit vulnerabilities, providing insights into how an adversary might
breach the system.
---
Q2. Which testing technique purposely sends random or malformed
input data to an application to expose security vulnerabilities and crash-
causing bugs?
A. Regression testing
B. Fuzz testing
C. Load testing
D. Integration testing
ANS: B (Fuzz testing)
Rationale: Fuzz testing exposes unexpected edge cases by feeding
random or unexpected inputs, revealing vulnerabilities and stability
issues.
---
Q3. In the context of threat modeling, what is the primary objective of
using frameworks such as STRIDE?
A. To generate encryption keys automatically
©2025
,B. To identify and categorize potential security threats
C. To validate user requirements
D. To automate penetration tests
ANS: B
Rationale: STRIDE helps analyze a system’s design by categorizing
threats—including Spoofing, Tampering, Repudiation, Information
Disclosure, Denial of Service, and Elevation of Privilege—so that
vulnerabilities can then be mitigated.
---
Q4. Which of the following accurately characterizes static security
testing techniques?
A. They involve executing the application in real time.
B. They inspect source code without running the application.
C. They simulate live network attacks to assess vulnerabilities.
D. They focus exclusively on user interface robustness.
ANS: B (They inspect source code without running the application)
Rationale: Static security testing (or static analysis) examines the
source code for security issues without executing the code, helping to
detect vulnerabilities early in the development lifecycle.
---
Q5. Which secure coding practice is most effective in preventing SQL
injection attacks?
A. Relying solely on client-side validation
B. Using regular expressions for input filtering
C. Employing parameterized queries or prepared statements
D. Logging all user input for later analysis
ANS: C (Employing parameterized queries or prepared statements)
Rationale: Parameterized queries separate SQL code from user input,
©2025
, thus preventing attackers from injecting malicious SQL commands.
---
Q6. In security testing, a “sandbox” environment is used to:
A. Run performance tests under high loads
B. Isolate potentially dangerous code to prevent harm to production
systems
C. Compile code in a secure manner
D. Generate vulnerability reports automatically
ANS: B
Rationale: A sandbox isolates code execution so that untrusted or
dangerous code can run in a controlled environment without
compromising production systems.
---
Q7. Which security principle mandates that users and system
components be granted only the minimum permissions necessary to
perform their functions?
A. Separation of duties
B. Defense in depth
C. Principle of least privilege
D. Fail-safe defaults
ANS: C (Principle of least privilege)
Rationale: The principle of least privilege minimizes risk by ensuring
each entity gets only the access it absolutely needs, reducing potential
abuse if compromised.
---
Q8. What is the primary objective of vulnerability scanning tools in the
context of security testing?
©2025