List of questions
Related questions
Question 464 - CAS-004 discussion
During a software assurance assessment, an engineer notices the source code contains multiple instances of strcpy. which does not verify the buffer length. Which of the following solutions should be integrated into the SDLC process to reduce future risks?
A.
Require custom IDS/IPS detection signatures for each type of insecure function found.
B.
Perform a penetration test before moving to the next step of the SDLC.
C.
Update the company's secure coding policy to exclude insecure functions.
D.
Perform DAST/SAST scanning before handoff to another team.
Your answer:
0 comments
Sorted by
Leave a comment first