QUESTIONS AND CORRECT AND CORRECT
ANSWERS (VERIFIED ANSWERS) Q&A 2026-
2027|INSTANT DOWNLOAD
1. Which principle ensures that software components receive
only the permissions necessary to perform their tasks?
A. Defense in depth
B. Least privilege
C. Separation of duties
D. Fail-open design
Correct Answer: B. Least privilege
Rationale: The principle of least privilege restricts users,
processes, and applications to only the access rights required to
complete their functions, reducing attack opportunities.
2. What is the primary goal of secure software design?
A. Increase software complexity
B. Eliminate all testing requirements
C. Reduce vulnerabilities throughout the software lifecycle
D. Improve application appearance
Correct Answer: C. Reduce vulnerabilities throughout the
software lifecycle
,Rationale: Secure software design focuses on preventing
vulnerabilities through planning, architecture, coding practices,
testing, and maintenance.
3. Which security practice involves considering security
requirements during the initial design phase?
A. Security by design
B. Patch management
C. Incident response
D. Penetration testing
Correct Answer: A. Security by design
Rationale: Security by design integrates security controls from
the beginning instead of adding them after development.
4. What type of vulnerability occurs when an application
executes unintended commands through user input?
A. Buffer overflow
B. Injection attack
C. Cross-site request forgery
D. Race condition
Correct Answer: B. Injection attack
Rationale: Injection vulnerabilities occur when untrusted input
is interpreted as commands or queries by an application.
,5. Which OWASP vulnerability involves inserting malicious
scripts into web pages viewed by users?
A. SQL injection
B. Cross-site scripting (XSS)
C. Broken authentication
D. Security misconfiguration
Correct Answer: B. Cross-site scripting (XSS)
Rationale: XSS allows attackers to execute malicious scripts in
another user’s browser.
6. What is the purpose of input validation in secure software
development?
A. Improve application graphics
B. Verify user input meets expected requirements
C. Increase database size
D. Remove authentication requirements
Correct Answer: B. Verify user input meets expected
requirements
Rationale: Input validation prevents malicious or unexpected
data from being processed by the application.
, 7. Which software development model integrates security
activities throughout the development process?
A. Waterfall only
B. Secure Software Development Lifecycle (SSDLC)
C. Rapid prototyping only
D. Hardware lifecycle model
Correct Answer: B. Secure Software Development Lifecycle
(SSDLC)
Rationale: SSDLC incorporates security practices during
planning, design, coding, testing, deployment, and
maintenance.
8. What security concept assumes systems will eventually fail
and prepares controls to limit damage?
A. Zero trust
B. Defense in depth
C. Obfuscation
D. Open design
Correct Answer: B. Defense in depth
Rationale: Defense in depth uses multiple security layers so
that one failed control does not compromise the entire system.
9. Which method helps identify vulnerabilities by analyzing
application source code?