Which of the following would MOST likely be included in the final report of a static application-security test that was written with a team of application developers as the intended audience?
A.
Executive summary of the penetration-testing methods used
B.
Bill of materials including supplies, subcontracts, and costs incurred during assessment
C.
Quantitative impact assessments given a successful software compromise
D.
Code context for instances of unsafe type-casting operations
I'll go with D for 2 reasons.
1. It's designed for app dev.
2. Answer C suggest that the app is already live so a dynamic code analysis would be better suited.
In a final report of a static application-security test aimed at application developers, it is important to provide specific details and code context related to the identified security issues. Unsafe type-casting operations are examples of potential vulnerabilities that should be highlighted, along with explanations of the associated risks and recommendations for remediation.
The other options mentioned in the question (a. Quantitative impact assessments, b. Executive summary, c. Bill of materials) are not typically included in a static application-security test report targeted at application developers.
The answer is D. Given the audience of application developers AND the need to close off the project, the step in D occurs in the attestation phase, where you have to provide evidence to confirm your findings.
This section is not available anymore. Please use the main Exam Page.PT1-002 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
BinarySoldier
Highly Voted 3 years, 5 months agoDavar39
3 years, 4 months agobieecop
Most Recent 1 year, 9 months agoMysterClyde
1 year, 11 months agokiduuu
3 years agoCharlieb123
3 years agobrandonl
3 years, 1 month agotokhs
3 years, 5 months ago