Vantage Cloud’s payments team suffers a breach traced to a s…

Vantage Cloud’s payments team suffers a breach traced to a specific flaw in how it handled API tokens. The engineering director insists the team not only patch it, but also write a new security requirement that encodes the fix, so the same class of defect can’t slip into future projects. A newer engineer on the team asks what idea this reflects. What’s the answer?

During a pre-launch security review of Northfield Retail’s c…

During a pre-launch security review of Northfield Retail’s checkout platform, the audit team finds a customer-profile page that renders a shopper’s saved display name straight into the HTML. A developer on the call argues it needs no special handling because the value came from Northfield’s own database and is therefore trusted — until the auditor points out that a display name saved months earlier is already firing a stored XSS payload in every visitor’s browser. What principle should have been applied?

You can upload any work or scratch paper here, please make s…

You can upload any work or scratch paper here, please make sure your scratch is labeled by question, if I cannot identify which problem the work is for I will not use the scratch.  It is best if you use a scanning app, I recommend you use  Genius Scan or Camscanner and note you can also upload your scratch in the exam module under Exam 1 scratch upload.  If none of that works you can email me your scratch paper within 10 minutes of the exam ending as well.