QuestionQ14

Security Test Techniques

Your company is launching a new web-based e-commerce platform that lets customers create accounts, browse products, and make purchases. Because the platform will integrate with payment gateways and process sensitive customer information, such as personal data and credit card details, the security team is concerned about vulnerabilities that attackers could exploit. To provide strong security, you want to conduct security testing that evaluates and mitigates the most common and critical web application security risks.

Which of the following would be MOST BENEFICIAL for the team to achieve this goal?

  • A ISO 27000
  • B OWASP
  • C CWE
  • D CVE
Explanation

OWASP provides web application security resources focused on identifying, testing for, and mitigating common high-impact risks. Its guidance, especially the OWASP Top 10, is directly applicable to an e-commerce application that processes sensitive personal and payment information.

Community Discussion

No comments yet. Be the first to start the discussion!