exam questions

Exam 312-39 All Questions

View all questions & answers for the 312-39 exam

Exam 312-39 topic 1 question 51 discussion

Actual exam question from ECCouncil's 312-39
Question #: 51
Topic #: 1
[All 312-39 Questions]

Wesley is an incident handler in a company named Maddison Tech. One day, he was learning techniques for eradicating the insecure deserialization attacks.
What among the following should Wesley avoid from considering?

  • A. Deserialization of trusted data must cross a trust boundary
  • B. Understand the security permissions given to serialization and deserialization
  • C. Allow serialization for security-sensitive classes
  • D. Validate untrusted input, which is to be serialized to ensure that serialized data contain only trusted classes
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Berro_b
1 week, 2 days ago
Selected Answer: C
p.826 and be carful to "AVOID" in the question. to Validate untrusted input which is to be serialized to ensure serialized data contains only trusted classes to Deserialization of trusted data must cross a trust boundary to Developers must re-architect their applications to Avoid serialization for security-sensitive classes to Guard sensitive data during deserialization to Filter untrusted serial data to Duplicate Security Manager checks enforced in a class during serialization and deserialization to Understand the security permissions given to serialization and deserialization
upvoted 1 times
...
lawrence1977
1 week, 6 days ago
Selected Answer: A
pg 826
upvoted 1 times
...
webberlee
9 months, 3 weeks ago
Selected Answer: D
Correct Answer is D
upvoted 1 times
webberlee
9 months, 3 weeks ago
Sorry!I make mistake, Answer is C.
upvoted 1 times
...
...
popocloud
1 year, 5 months ago
Answer is C according to CSA coursework Module 6 pg 826
upvoted 3 times
eshe
1 year, 3 months ago
Answer is D: Module 06 pg 826 says: Avoid serialization for security-sensitive classes. Not allow.
upvoted 1 times
eshe
1 year, 3 months ago
Sorry for my mistake, answer is C
upvoted 1 times
...
...
...
l3arner
1 year, 6 months ago
The answer is D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago