QuestionQ19

Human Factors in Security Testing

Based solely on the information above, which ONE of the following statements is your manager most likely to make?

Explanation

Client-side logic and values sent from a browser can be modified by the user, so correctness decisions that affect exam results must be independently enforced on the server. The report needs to describe the exploitable impact—how tampering with the client-supplied result could compromise the exam—rather than only identify the client-side behavior. OWASP guidance states that security-relevant validation must be performed server-side because client-side validation can be bypassed.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!