Solved

A Penetration Tester Is Testing a Web Application and Is

Question 90

Multiple Choice

A penetration tester is testing a web application and is logged in as a lower-privileged user. The tester runs arbitrary JavaScript within an application, which sends an XMLHttpRequest, resulting in exploiting features to which only an administrator should have access. Which of the following controls would BEST mitigate the vulnerability?


A) Implement authorization checks.
B) Sanitize all the user input.
C) Prevent directory traversal.
D) Add client-side security controls

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions