A company hires a professional to perform penetration testing. The tester has identified and verified that one web application is vulnerable to SQL injection and cross-site scripting attacks. Which technical control measure should the tester recommend to the company?

  • user input sanitization
  • multifactor authentication
  • process-level remediation
  • role-based access control (RBAC)
Explanation & Hints:

