CISSP Official Practice Tests by Mike Chapple, David Seidl

(chelsyfait) #1

Chapter 12 ■ Practice Test 4 311




  1. Kathleen has been asked to choose a highly formalized code review process for her soft-
    ware quality assurance team to use. Which of the following software testing processes is
    the most rigorous and formal?
    A. Fagan
    B. Fuzzing
    C. Over the shoulder
    D. Pair programming




  2. Frank is attempting to protect his web application against cross-site scripting attacks.
    Users do not need to provide input containing scripts, so he decided the most effective
    way to filter would be to write a filter on the server that watches for the