Question 1 of 30
Examination of the data shows that a new feature is being developed for a financial transaction processing application. This feature will allow users to upload scanned copies of receipts for expense reimbursement. Given the sensitive nature of financial data and the potential for new attack vectors, what is the most appropriate approach to ensure the security architecture of this new feature is robust and compliant?
Conduct a detailed threat modeling exercise for the new receipt upload functionality, identifying potential vulnerabilities and designing specific security controls to mitigate identified risks, integrating these into the development lifecycle from the outset.
Perform a comprehensive penetration test on the feature after its development is complete to identify any security weaknesses.
Apply a standard set of pre-defined security controls that are generally effective for web applications, without a specific analysis of the receipt upload feature's unique risks.
Assume that the application's existing security controls are sufficient to protect the new receipt upload functionality and proceed with development without further specific security analysis.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free