Problem Statement
Which choice is a practical fix under A02: Cryptographic Failures?
Explanation
Cryptographic failures are often about misusing crypto or leaking sensitive data. Use TLS everywhere, set HSTS, choose modern ciphers, and keep secrets out of logs and URLs.
OWASP’s Top 10 reframed this area from “Sensitive Data Exposure” to focus on root crypto and data handling mistakes.
Code Solution
SolutionRead Only
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
