Questions

  1. What security assessment may apply to a new or major application release?
    1. Full assessment
    2. Assessment based on the patch scope
    3. Assessment based on the third party and the integration interfaces
    4. The security testing scope is limited to ensure no major security issues
  2. Which of the following is not one of the self-assessment activities that should be done by the product development team?
    1. Review the OWASP ASVS checklist
    2. Security awareness training program
    3. Execute defined automated security tools, such as ZAP, NMAP, and SQLmap
    4. Fix major security issues
  3. Which of the following is not the security testing approach for checking hidden communication interfaces?
    1. Listening to 0.0.0.0 is forbidden
    2. Searching for hidden hard-coded secrets, ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.