Web application security requires multiple layered approaches. Input validation prevents injection attacks, security policies provide governance, and removing hidden files reduces information disclosure. All three measures listed (1, 2, and 3) are essential security practices, making option E (all) the comprehensive correct answer.