To save time, a company that is developing a new VPN solution has decided to use the OpenSSL library within its proprietary software. Which of the following should the company consider to maximize risk reduction from vulnerabilities introduced by OpenSSL? A. Include stable, long-term releases of third-party libraries instead of using newer versions. B. Ensure the third-party library implements the TLS and disable weak ciphers. C. Compile third-party libraries into the main code statically instead of using dynamic loading. D. Implement an ongoing, third-party software and library review and regression testing. Â Suggested Answer: D Community Answer: D This question is in CAS-004 CompTIA Advanced Security Practitioner (CASP+) Exam For getting CompTIA Advanced Security Practitioner (CASP+) Certificate Disclaimers: The website is not related to, affiliated with, endorsed or authorized by CompTIA. Trademarks, certification & product names are used for reference only and belong to CompTIA. The website does not contain actual questions and answers from CompTIA's Certification Exams.
Please login or Register to submit your answer