- Home
- All questions
- Question 144
CompTIA Security+ study material · question 144 of 611
Which validation strategy does OWASP recommend, and why?
Show the answer
Answer: B. Allow-listing, because attackers reliably find inputs a deny-list has not anticipated
An allow-list defines what is acceptable; a deny-list must anticipate every bad variant and always trails the attacker.
Source: OWASP Input Validation Cheat Sheet (OWASP) — OWASP Input Validation Cheat Sheet › Validation