Study. uk . com
  1. Home
  2. All questions
  3. Question 157

CompTIA Security+ study material · question 157 of 611

Which two application controls most directly limit denial-of-service exposure? Choose two.

  1. Longer session timeouts
  2. Verbose error messages for debugging
  3. Rate limiting per caller
  4. Resource quotas on expensive operations
Show the answer

Answer: C. Rate limiting per caller
D. Resource quotas on expensive operations

Both cap what any single caller can consume. Longer sessions and verbose errors make the problem worse.

Source: OWASP Denial of Service Cheat Sheet (OWASP) — OWASP Denial of Service Cheat Sheet › Defenses

Challenge yourself on this topic → Study as cards