adplus-dvertising
frame-decoration

Question

Why might developers use input blacklisting instead of input whitelisting?

a.

Input blacklisting is more efficient

b.

Input blacklisting is easier to implement

c.

Input whitelisting is not effective

d.

Input whitelisting is difficult due to the nature of user input fields

Answer: (d).Input whitelisting is difficult due to the nature of user input fields Explanation:Developers might use input blacklisting when it is challenging to perform input whitelisting due to the nature of user input fields.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. Why might developers use input blacklisting instead of input whitelisting?

Similar Questions

Discover Related MCQs

Q. What challenge might developers face when implementing input whitelisting for a field that allows users to input product descriptions in a classified ad application?

Q. What consideration must developers keep in mind when performing input validation to avoid impacting legitimate input?

Q. What is parameter pollution in the context of web application security?

Q. How does parameter pollution work in injecting SQL code into a web application?

Q. Why might an attacker use the parameter pollution technique with two different values for the same input variable?

Q. What assumption does a parameter pollution attack rely on?

Q. How do parameter pollution attacks persist despite most modern platforms defending against them?

Q. What is the primary role of Web Application Firewalls (WAFs) in web application security?

Q. In which layer do Web Application Firewalls (WAFs) operate?

Q. What is the significance of input validation in the context of injection attacks?

Q. When might injection flaws still occur in web applications despite input validation?

Q. What does a Web Application Firewall (WAF) scrutinize to prevent malicious traffic?

Q. What is the primary objective of SQL injection attacks in web applications?

Q. In a basic SQL injection attack, what does the attacker ideally want to do after providing input to the web application?

Q. When might a web application with SQL injection flaws not provide the attacker with the ability to directly view the results of the attack?

Q. What is the purpose of blind SQL injection attacks?

Q. In Boolean blind SQL injection, what does the attacker test through injected code before attempting the attack?

Q. How does an attacker perform testing in Boolean blind SQL injection after injecting code into the account number field?

Q. What query would be sent to the database in a successful Boolean SQL injection attack with the input '52019' OR 1=1;--?

Q. What does an attacker infer if the web application returns a page with no results after providing input '52019' AND 1=2;--?