An organization's web servers host an online ordering system. The organization discovers that the servers are vulnerable to a malicious JavaScript injection, which could allow attackers to access customer payment information. Which of the following mitigation strategies would be most effective for preventing an attack on the organization's web servers? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Regularly updating server software and patches, Utilizing a web-application firewall.
Why this is the answer
Regularly updating server software and patches is crucial because it addresses known vulnerabilities, including those that could be exploited by malicious JavaScript injection. Software vendors release patches to fix security flaws, and applying these promptly closes potential attack vectors. Utilizing a web-application firewall (WAF) is highly effective as it inspects HTTP traffic and can detect and block malicious input, such as JavaScript injection attempts, before they reach the web servers. Implementing strong password policies, while important for overall security, doesn't directly prevent code injection. Encrypting data protects it if a breach occurs but doesn't prevent the injection itself. Performing regular vulnerability scans identifies issues but doesn't mitigate them. Removing payment information would prevent its theft but isn't a direct mitigation for the injection vulnerability itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed