CompTIA CASP+ CAS-004 – Question062

A security architect is implementing a web application that uses a database back end. Prior to the production, the architect is concerned about the possibility of XSS attacks and wants to identify security controls that could be put in place to prevent these attacks.
Which of the following sources could the architect consult to address this security concern?

A.
SDLC
B. OVAL
C. IEEE
D. OWASP