Study. uk . com
  1. Home
  2. All questions
  3. Question 598

CompTIA Security+ study material · question 598 of 611

Which two events should an application always log? Choose two.

  1. Access control failures
  2. The plaintext of rejected passwords
  3. Input validation failures
  4. Every successful page render
Show the answer

Answer: A. Access control failures
C. Input validation failures

Both indicate probing. Credentials must never be logged, and logging every render produces noise without signal.

Source: OWASP Logging Cheat Sheet (OWASP) — OWASP Logging Cheat Sheet › Which events to log

Challenge yourself on this topic → Study as cards