Study. uk . com
  1. Home
  2. All questions
  3. Question 160

CompTIA Security+ study material · question 160 of 611

A production application returns full stack traces including framework versions when an error occurs. Beyond untidiness, what does this give an attacker?

  1. Reconnaissance they would otherwise have to guess at
  2. A bypass of the Content Security Policy
  3. A valid session identifier
  4. The ability to inject code through the error page
Show the answer

Answer: A. Reconnaissance they would otherwise have to guess at

Leaked versions, paths and query fragments tell the attacker which exploits are worth trying.

Source: OWASP Top 10 (OWASP) — OWASP Top Ten › Security Misconfiguration

Challenge yourself on this topic → Study as cards