IBM Security AppScan Source Edition Implementation 認定 C2150-810 試験問題:
1. Which two languages can be scanned by the AppScan Source CLI?
A) C++
B) Haskell
C) ActionScript
D) Java
E) Fortran
2. Which AppScan component is required to create PBSA rules?
A) AppScan Source for Remediation
B) AppScan Source for Automation
C) AppScan Source for Development
D) AppScan Source for Analysis
3. Which two licenses can be used for AppScan Source IDE plug-ins?
A) IBM Security AppScan Source for Developer
B) IBM Security AppScan Source for Automation
C) IBM Security AppScan Source for Remediation
D) IBM Security AppScan Source for Quality
E) IBM Security AppScan Source for Analysis
4. In order to publish Assessments to AppScan Enterprise Console for the first time, which settings must be configured?
A) InAppScan Enterprise Server settings, in the Jazz Team Server preference page
B) InAppScan Source settings, in the Application Server preference page
C) InAppScan Source settings, in the AppScan Enterprise Console preference page
D) InAppScan Enterprise Server settings, in the Microsoft SQL server preference page
5. You are reviewing a thick client application and come upon File Injection findings in a function that opens zip files and extracts data from them, but the customer you are working with tells you that the data is sanitized using a method mySanitizer.validateZip{..). You confirm this and decide to remove this vulnerability and other File injection findings with sanitized data using the Remove functionality of the Trace section in the Filter Editor.
In which area of the Trace Rule Entry dialog would you add mySanitizer.validateZip(..) method?
A) Source section
B) Prohibited Calls section
C) Sink section
D) Required Calls section
質問と回答:
質問 # 1 正解: A、D | 質問 # 2 正解: C | 質問 # 3 正解: A、B | 質問 # 4 正解: C | 質問 # 5 正解: A |