An attacker attempts to overwhelm an API by sending thousands of requests per second from a single client. Which mitigation technique is MOST effective against this threat?
A. EncryptionWhich design and development deliverable contains the results of each type of evaluation that was performed and the type and number of vulnerabilities discovered?
A. Security test execution reportA potential threat was discovered during automated system testing when a PATCH request sent to the API caused an unhandled server exception. The API only supports GET. POST. PUT, and DELETE requests. How should existing security controls be adjusted to prevent this in the future?
A. Property configure acceptable API requestsWhile performing functional testing of the new product from a shared machine, a QA analyst closed their browser window but did not logout of the application. A different QA analyst accessed the application an hour later and was not prompted to login. They then noticed the previous analyst was still logged into the application. How should existing security controls be adjusted to prevent this in the future?
A. Ensure no sensitive information is stored in plain text in cookiesWhat are the three primary goals of the secure software development process?
A. Performance, reliability, and maintainabilityWhich privacy impact statement requirement type defines how personal information will be protected when authorized or independent external entities are involved?
A. Personal information retention requirementsWhat are the eight phases of the software development lifecycle (SDLC)?
A. Planning, security analysis, requirement analysis, design, implementation, threat mitigation, testing, maintenanceWhat is the last slop of the SDLOSDL code review process?
A. Review for security issues unique to the architectureA security team evaluates how user data moves from a web form through business logic and into a database during a manual review. Which manual code review technique is being applied?
A. Control flow analysisWhich DREAD category is based on how easily a threat exploit can be found?
A. Damage PotentialNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only WGU University exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your WGU-KEO1 exam preparations and WGU University certification application, do not hesitate to visit our Vcedump.com to find your solutions here.