Open cardosec

Case DFA42D · Web AppSec · L2 Practitioner

Prioritising the OWASP Top 10

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Broken access control is found in nearly every app tested and scanners rarely catch it, since it needs business-logic context
  2. Categories favour root causes over symptoms (Cryptographic Failures, not Sensitive Data Exposure) so they point at a fix
  3. Lists shift with data and threats: 2021 added Insecure Design and SSRF; 2025 folded SSRF into A01 and added supply chain
  4. Ranking mixes contributed test data with a practitioner survey, so risks tools rarely detect can still make the list
  5. Use it as an awareness and prioritisation baseline, not a testing standard; verify against OWASP ASVS requirements

If the interviewer pushes back

  • Why would Insecure Design not be fixable by a perfect implementation, and what practice addresses it?
  • A vendor claims their scanner gives full OWASP Top 10 coverage. What would you challenge, and why?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.