312-96無料認定試験材料はこちらの49問題 [Q16-Q32]

Share

312-96無料認定試験材料はこちらの49問題

リアル312-96は100%カバー率リアル試験問題を試そう!

質問 # 16
A developer has written the following line of code to handle and maintain session in the application. What did he do in the below scenario?

  • A. Maintained session by creating a Cookie user with value stored in uname variable.
  • B. Maintained session by creating a HTTP variable user with value stored in uname variable.
  • C. Maintained session by creating a hidden variable user with value stored in uname variable.
  • D. Maintained session by creating a Session variable user with value stored in uname variable.

正解:D


質問 # 17
In a certain website, a secure login feature is designed to prevent brute-force attack by implementing account lockout mechanism. The account will automatically be locked after five failed attempts. This feature will not allow the users to login to the website until their account is unlocked. However, there is a possibility that this security feature can be abused to perform __________ attack.

  • A. Unvalidated Redirects and Forwards
  • B. Denial-of-Service [Do
  • C. Failure to Restrict URL
  • D. Broken Authentication

正解:B


質問 # 18
Which of the risk assessment model is used to rate the threats-based risk to the application during threat modeling process?

  • A. DREAD
  • B. RED
  • C. STRIDE
  • D. SMART

正解:C


質問 # 19
Which of the following configurations can help you avoid displaying server names in server response header?

  • A. < Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" ServerName=" disable" redirectPort="8443" / >
  • B. < Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" Server = " " redirectPort="8443" / >
  • C. < Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" ServerName ="null " redirectPort="8443'' / >
  • D. < Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort= "8443" / >

正解:A


質問 # 20
The threat modeling phase where applications are decomposed and their entry points are reviewed from an attacker's perspective is known as ________

  • A. Threat Classification
  • B. Threat Identification
  • C. Attack Surface Evaluation
  • D. Impact Analysis

正解:C


質問 # 21
Which of the following relationship is used to describe security use case scenario?

  • A. Threatens Relationship
  • B. Include Relationship
  • C. Mitigates Relationship
  • D. Extend Relationship

正解:D


質問 # 22
Which of the following configuration settings in server.xml will allow Tomcat server administrator to impose limit on uploading file based on their size?

  • A. < connector... maxPostSize="file size" / >
  • B. < connector... maxFileSize="file size" / >
  • C. < connector... maxPostSize="0"/>
  • D. < connector... maxFileLimit="file size" / >

正解:A


質問 # 23
Which of the following method will help you check if DEBUG level is enabled?

  • A. EnableDebug ()
  • B. DebugEnabled()
  • C. IsEnableDebug ()
  • D. isDebugEnabled()

正解:D


質問 # 24
Which of the following relationship is used to describe abuse case scenarios?

  • A. Include Relationship
  • B. Mitigates Relationship
  • C. Threatens Relationship
  • D. Extend Relationship

正解:C


質問 # 25
Identify the formula for calculating the risk during threat modeling.

  • A. IRISK = PROBABILITY * VULNERABILITY
  • B. RISK = PROBABILITY * DAMAGE POTENTIAL
  • C. RISK = PROBABILITY " ASSETS
  • D. RISK = PROBABILITY "Attack

正解:B


質問 # 26
Suppose there is a productList.jsp page, which displays the list of products from the database for the requested product category. The product category comes as a request parameter value. Which of the following line of code will you use to strictly validate request parameter value before processing it for execution?

  • A. public boolean validateUserName() {String CategoryId= request.getParameter("CatId");}
  • B. public boolean validateUserName() { if(request.getParameter("CatId")!=null ) String CategoryId=request.getParameter("CatId");}
  • C. public.boolean validateUserName() { if(!request.getParamcter("CatId").equals("null"))}
  • D. public boolean validateUserName() { Pattern p = Pattern.compile("[a-zA-Z0-9]*$"); Matcher m = p.matcher(request.getParameter(CatId")); boolean result = m.matches(); return result;}

正解:D


質問 # 27
Identify the type of attack depicted in the following figure.

  • A. Directory Traversal Attack
  • B. Form Tampering Attack
  • C. Denial-of-service attack
  • D. SQL Injection attack

正解:A


質問 # 28
Alice, a security engineer, was performing security testing on the application. He found that users can view the website structure and file names. As per the standard security practices, this can pose a serious security risk as attackers can access hidden script files in your directory. Which of the following will mitigate the above security risk?

  • A. < int-param > < param-name>listinqs < param-value>true < /init-param
  • B. < int param > < param-name>directorv-listinqs < param-value>false < /init-param >
  • C. < int-param > < param-name>directory-listinqs < param-value>true < /init-param >
  • D. < int-param > < param-name>listinqs < param-value>false < /init-param >

正解:B


質問 # 29
Identify the type of encryption depicted in the following figure.

  • A. Digital Signature
  • B. Symmetric Encryption
  • C. Hashing
  • D. Asymmetric Encryption

正解:B


質問 # 30
Which of the following state management method works only for a sequence of dynamically generated forms?

  • A. Sessions
  • B. Cookies
  • C. Hidden Field
  • D. URL-rewriting

正解:C


質問 # 31
Ted is an application security engineer who ensures application security activities are being followed during the entire lifecycle of the project. One day, he was analyzing various interactions of users depicted in the use cases of the project under inception. Based on the use case in hand, he started depicting the scenarios where attacker could misuse the application. Can you identify the activity on which Ted is working?

  • A. Ted was depicting abstract use cases
  • B. Ted was depicting lower-level use cases
  • C. Ted was depicting abuse cases
  • D. Ted was depicting security use cases

正解:C


質問 # 32
......

312-96試験問題集簡単なまとめ:https://jp.fast2test.com/312-96-premium-file.html


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어