Question
Which practice avoids a common mistake with JSON Serialization vs pickle?
- Ignore the JSON Serialization vs pickle issue and rely on team discipline instead of clearer APIs or invariants.
- Silence the JSON Serialization vs pickle problem by using broad catches, hidden globals, or extra shared mutable state.
- Prefer the version of JSON Serialization vs pickle that makes behavior less predictable as long as the code still runs.
- Do not use pickle with untrusted input because deserialization can execute behavior and violates safe-boundary assumptions.
Hint
Look for the option that protects correctness instead of hiding the problem.
Answer and rationale
Correct answer: D. Do not use pickle with untrusted input because deserialization can execute behavior and violates safe-boundary assumptions.
Do not use pickle with untrusted input because deserialization can execute behavior and violates safe-boundary assumptions. This is a common failure mode in real Python code and a frequent interview follow-up.
Track: Python