Study. uk . com
  1. Home
  2. All questions
  3. Question 474

CISSP study material · question 474 of 500

How does OWASP define insecure design in the 2025 Top 10?

  1. Any weakness in the application's architecture diagram.
  2. Any weakness that appears before the coding phase.
  3. Any weakness that a threat model would have caught.
  4. Missing or ineffective control design.
Show the answer

Answer: D. Missing or ineffective control design.

OWASP frames the category around control design that is absent or ineffective, gathering a broad set of weaknesses under that single idea.

Source: OWASP Top 10 A06:2025 (OWASP) — OWASP Top 10:2025 A06 Insecure Design > Description

Challenge yourself on this topic → Study as cards