WorksheetsLO5 SR
Total questions: 8
Worksheet time: 4mins
Which is not an industry standard report template
OWASP Top 10 2013
NST Special Publication 800-53
International Standard – ISO 27002
WASC Threat Classification V10.0
How Appscan detects and XSS vulnerability?
By embedding a script in the page response
Because the response contains a redirection
Because the response contains SQL Server error
Because the Test Response (on the right) is identical to the Original Response (on the left)
What IS NOT an Appscan Standard Feature?
JavaScript and Ajax web crawling
Adobe Flash and Flex crawling
Glass box-assisted crawling
Graphic image crawling
How we can see the cookies information in Appscan?
By accessing the Application Data view, then click on Cookies
By accessing the Security Issues view, then click on Cookies
By accessing the Remediation Tasks view issues view, then click on Cookies
None of the above
Which type of attack relies on an authenticated user to click a malicious link to perform an unintended action on the target application?
SQL Injection
Directory traversal
Cross Site Scripting
Cross-Site request forgery
What is the policy that returns an overwhelming number of results?
Developer
Complete
Essential
Vital view Fiew
How to identify that a user interaction is needed in a web page?
Check "User interactive needed" tab in the Application Data view
Check "User interactive needed" tab in the Security Issues view
Check "User interactive needed" tab in the Remediation Tasks view
None of the above
What the following filter description is related to"?
"Determine whether the filtered links are redundant; if not, increase the path limit and re- explore":
Untested Web Server
Depth Limit
Path Limit
None of the above
