2023年最新の312-96試験解答最新版PassTest 312-96のPDF問題集をダウンロードせよ(49問題と解答)
無料2023年最新のApplication Security 312-96問題集を提供しております!PassTest
質問 # 17
Identify the type of attack depicted in the following figure.
- A. Directory Traversal Attack
- B. SQL Injection attack
- C. Form Tampering Attack
- D. Denial-of-service attack
正解:A
質問 # 18
Which of the following configurations can help you avoid displaying server names in server response header?
- A. < Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" Server = " " redirectPort="8443" / >
- B. < Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" ServerName ="null " redirectPort="8443'' / >
- C. < Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" ServerName=" disable" redirectPort="8443" / >
- D. < Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort= "8443" / >
正解:C
質問 # 19
Which of the following DFD component is used to represent the change in privilege levels?
- A. 0
- B. 1
- C. 2
- D. 3
正解:B
質問 # 20
Identify the type of attack depicted in the figure below:
- A. Denial-of-Service attack
- B. Cross-Site Request Forgery (CSRF) attack
- C. SQL injection attack
- D. XSS
正解:B
質問 # 21
Thomas is not skilled in secure coding. He neither underwent secure coding training nor is aware of the consequences of insecure coding. One day, he wrote code as shown in the following screenshot. He passed 'false' parameter to setHttpOnly() method that may result in the existence of a certain type of vulnerability. Identify the attack that could exploit the vulnerability in the above case.
- A. Directory Traversal Attack
- B. Denial-of-Service attack
- C. SQL Injection Attack
- D. Client-Side Scripts Attack
正解:D
質問 # 22
Alice, a Server Administrator (Tomcat), wants to ensure that Tomcat can be shut down only by the user who owns the Tomcat process. Select the appropriate setting of the CATALINA_HOME/conf in server.xml that will enable him to do so.
- A. < server port="-1" shutdown="SHUTDOWN" >
- B. < server port="" shutdown-"' >
- C. < server port="8080" shutdown="SHUTDOWN" >
- D. < server port="-1" shutdown-*" >
正解:D
質問 # 23
Which of the following state management method works only for a sequence of dynamically generated forms?
- A. Hidden Field
- B. Cookies
- C. Sessions
- D. URL-rewriting
正解:A
質問 # 24
Suppose there is a productList.jsp page, which displays the list of products from the database for the requested product category. The product category comes as a request parameter value. Which of the following line of code will you use to strictly validate request parameter value before processing it for execution?
- A. public boolean validateUserName() { Pattern p = Pattern.compile("[a-zA-Z0-9]*$"); Matcher m = p.matcher(request.getParameter(CatId")); boolean result = m.matches(); return result;}
- B. public boolean validateUserName() {String CategoryId= request.getParameter("CatId");}
- C. public.boolean validateUserName() { if(!request.getParamcter("CatId").equals("null"))}
- D. public boolean validateUserName() { if(request.getParameter("CatId")!=null ) String CategoryId=request.getParameter("CatId");}
正解:A
質問 # 25
Alice, a security engineer, was performing security testing on the application. He found that users can view the website structure and file names. As per the standard security practices, this can pose a serious security risk as attackers can access hidden script files in your directory. Which of the following will mitigate the above security risk?
- A. < int-param > < param-name>listinqs < param-value>true < /init-param
- B. < int param > < param-name>directorv-listinqs < param-value>false < /init-param >
- C. < int-param > < param-name>directory-listinqs < param-value>true < /init-param >
- D. < int-param > < param-name>listinqs < param-value>false < /init-param >
正解:B
質問 # 26
Which of the following can be derived from abuse cases to elicit security requirements for software system?
- A. Misuse cases
- B. Security use cases
- C. Data flow diagram
- D. Use cases
正解:B
質問 # 27
During his secure code review, John, an independent application security expert, found that the developer has used Java code as highlighted in the following screenshot. Identify the security mistake committed by the developer?
- A. He is trying to use Whitelisting Input Validation
- B. He is trying to use Blacklisting Input Validation
- C. He is trying to use Parametrized SQL Query
- D. He is trying to use Non-parametrized SQL query
正解:D
質問 # 28
Jacob, a Security Engineer of the testing team, was inspecting the source code to find security vulnerabilities.
Which type of security assessment activity Jacob is currently performing?
- A. CAST
- B. CAST
- C. SAST
- D. ISCST
正解:C
質問 # 29
A US-based ecommerce company has developed their website www.ec-sell.com to sell their products online. The website has a feature that allows their customer to search products based on the price. Recently, a bug bounty has discovered a security flaw in the Search page of the website, where he could see all products from the database table when he altered the website URL http://www.ec-sell.com/products.jsp?val=100 to http://www.ec-sell.com/products.jsp?val=200 OR '1'='1 -. The product.jsp page is vulnerable to
- A. SQL Injection attack
- B. Brute force attack
- C. Session Hijacking attack
- D. Cross Site Request Forgery attack
正解:A
質問 # 30
Which of the following relationship is used to describe abuse case scenarios?
- A. Threatens Relationship
- B. Mitigates Relationship
- C. Include Relationship
- D. Extend Relationship
正解:A
質問 # 31
Which of the following is used to mapCustom Exceptions to Statuscode?
- A. @ResponseCode
- B. @ResponseStatus
- C. @ResponseStatusCode
- D. @ScacusCode
正解:B
質問 # 32
......
312-96試験解答問題集:https://www.passtest.jp/ECCouncil/312-96-shiken.html(49問題と解答)
無料2023年最新のApplication Security 312-96問題集を提供しております!PassTest:https://drive.google.com/open?id=1aYQ20xA8N93ZHVngJAhDCMZhmnpU7W4o