Security Assessment and Testing Question #64

During misuse case testing for a new web application, you identify a threat where an attacker exploits the data encryption feature to gain unauthorized access. What is the most appropriate next action?

A. Develop a test case that simulates the identified misuse case, execute the test, and observe the application’s response.
B. Immediately inform all users about the potential vulnerability and advise them to avoid the feature.
C. Ignore the potential misuse case since encryption is intended to enhance security.
D. Remove the data encryption feature from the application to eliminate the vulnerability.
Domain Concept: Security Assessment and Testing

This scenario evaluates management-level decision making in Security Assessment and Testing. In CISSP exam scenarios, evaluate answers through executive governance, risk assessment, life safety, and due diligence before implementing technical controls.

💡 View the Answer & Detailed Explanation

The correct answer to this scenario-based question requires an understanding of the CISSP Managerial Mindset. Register to view our in-depth explanation and access 1100+ adaptive questions completely free.

Fuel the Mission ☕

Keep the vault updated and the servers running.

$
Secure Payment via PayPal

Verified Excellence

Spread the Word

If you like us, share us with your peers.

Scroll to Top