A penetration tester has completed an analysis of the various software products produced by the company under assessment. The tester found that over the past several years the company has been including vulnerable third-party modules in multiple products, even though the quality of the organic code being developed is very good. Which of the following recommendations should the penetration tester include in the report?
A) Add a dependency checker into the tool chain.
B) Perform routine static and dynamic analysis of committed code.
C) Validate API security settings before deployment.
D) Perform fuzz testing of compiled binaries.
Correct Answer:
Verified
Q27: A penetration tester writes the following script:
Q28: A company that requires minimal disruption to
Q29: A penetration tester wants to identify CVEs
Q30: A penetration tester is testing a web
Q31: A penetration tester who is conducting a
Q33: A red-team tester has been contracted to
Q34: A penetration tester wants to scan a
Q35: A penetration tester runs the following command
Q36: A penetration tester has obtained root access
Q37: A penetration tester logs in as a
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents