QuestionQ18

Security Testing Processes

The risks identified for a traffic-control system include authentication and authorization risks, SQL injection attacks, the system entering invalid states such as multiple green lights, man-in-the-middle attacks, and network-borne attacks.

Which ONE of the following abstract tests does NOT relate to any risk identified in the risk assessment?

Explanation

Authorization testing, authentication-method testing, and interception/tampering testing address the stated authorization, authentication, and man-in-the-middle risks. Testing large inputs for memory problems addresses resource or memory robustness concerns, which are not identified in the listed risk assessment.

Community Discussion

No comments yet. Be the first to start the discussion!