Skip to main content

C2150-199 Real Exam Questions

IBM Security AppScan Standard Edition Implementation v8.7

55 questions available · Page 1 of 6

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

What are two acceptable methods to protect sensitive user data?

  1. A

    Hashing

  2. B

    URL Encoding

  3. C

    DES Encryption

  4. D

    AES Encryption

  5. E

    Base 64 Encoding

Show answer and explanation

Correct answers: B, E

Question 2 Single choice

In the Automatic Form Fill window, if the URL field is blank for a particular row, which value will be passed for that row's parameter?

  1. A

    Blank

  2. B

    That row's parameter value

  3. C

    The parameter will be skipped.

  4. D

    The value of the "Fill unknown fields with" box

Show answer and explanation

Correct answer: B

Question 3 Single choice

The starting URL is: http://www.mysite.com/myfolder/index.aspx. You want to restrict the scan to thefolder:http://www.mysite.com/myfolder/.

How should you configure the scan?

  1. A

    1. Add an Exclude item with path http://www.mysite.com/myfolder/2. Add an Exception item below the Exclude item, with the path of the folder to be scanned:http://www.mysite.com/

  2. B

    1. Add an Exception item with path http://www.mysite.com/myfolder/2. Add an Exclude item below theExclude item, with the path of the folder to be scanned:http://www.mysite.com

  3. C

    1. Add an Exclude item with path http://www.mysite.com/2. Add an Exception item below the Exclude item, with the path of the folder to be canned:http://www.mysite.com/myfolder/

  4. D

    1. Add an Exception item with path http://www.mysite.com/2. Add an Exclude item below the Excludeitem, with the path of the folder to be scanned:http://www.mysite.com/myfolder/

Show answer and explanation

Correct answer: B

Question 4 Multiple choice

Which three environment definitions are options in Scan Configuration?

  1. A

    Type of Site

  2. B

    Browser Type

  3. C

    System Memory

  4. D

    Application Server

  5. E

    Deployment Method

  6. F

    Database Character Set

Show answer and explanation

Correct answers: A, D, E

Question 5 Single choice

You need a template-based report of all the issue ID and variants found by a scan.

How should you create this?

  1. A

    «AS:lssueTypeRepeaterStart» «AS:lssueRepeaterStart» «AS:VariantlD» «AS:VariantTestRequest»
    «AS:lssueRepeaterEnd» «AS:lssueTypeRepeaterEnd»

  2. B

    «AS:lssueTypeRepeaterStart» «AS:VariantlD» «AS:VariantTestRequest»
    «AS:lssueTypeRepeaterEnd»

  3. C

    «AS:lssueTypeRepeaterStatt» «AS:RemediationRepeaterStart» «AS:VariantlD»
    «AS:VariantTestRequest» «AS:RemediationRepeaterEnd» «AS:lssueTypeRepeaterEnd»

  4. D

    «AS:lssueTypeRepeaterStart» «AS:VuInerableRepeaterStart» «AS:VariantlD»
    «AS:VariantTestRequest» «AS:VulnerableRepeaterEnd» «AS:IssueTypeRepeaterEnd»

Show answer and explanation

Correct answer: A

Question 6 Multiple choice

Which two login methods allows you to create a login sequence?

  1. A

    None

  2. B

    Prompt

  3. C

    Recorded

  4. D

    Multi-step

  5. E

    Automatic

Show answer and explanation

Correct answers: B, C

Question 7 Multiple choice

Which three finding types can the IBM Security AppScan Standard Edition malware module identify?

  1. A

    Link Injections

  2. B

    Broken external links

  3. C

    Unwanted internal links

  4. D

    Malicious external links

  5. E

    Unwanted external links

  6. F

    Unclassified external links

Show answer and explanation

Correct answers: D, E, F

Question 8 Single choice

The application you are testing contains links to external websites. You want to restrict the scan to the
designated web application URL.

Which configuration option should you use?

  1. A

    Enable Scan only links in and below this directory.

  2. B

    Add links to external website to the Exclude Paths list.

  3. C

    AppScan automatically identifies the website during a test.

  4. D

    Edit the hosts file to map the production website to the test website.

Show answer and explanation

Correct answer: A

Question 9 Single choice

Which statement is true about Privilege Escalation?

  1. A

    It requires only one scan to be run.

  2. B

    It can be detected by inadvertently triggered security issues.

  3. C

    IBM Security AppScan Standard Edition cannot perform Privilege Escalation.

  4. D

    Scans being compared must have the same scan configuration and equivalent explore data.

Show answer and explanation

Correct answer: D

Question 10 Single choice

In the Redundancy tuning of Parameters and Cookies view, the following option is disabled,
- Explore the URL again whenever this parameter/cookie is added or removed.

  1. A

    ...page.jsp will not be explored
    ...page.jsp?thisParam=Value will be explored

  2. B

    ...page.jsp will be explored
    ...page.jsp?thisParam=Value will be explored

  3. C

    ...page.jsp will be explored
    ...page.jsp?thisParam=Value will not be explored

  4. D

    ...page.jsp will not be explored
    ...page.jsp?thisParam=Value will not be explored

Show answer and explanation

Correct answer: A