Skip to main content

C2150-810 Real Exam Questions

IBM Security AppScan Source Edition Implementation

50 questions available · Page 1 of 5

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

What is "Automatic Propagator Markup" advanced setting in Scan Configuration view?

  1. A

    It marks all sinks as "taint propagators".

  2. B

    It marks all sources as "taint propagators".

  3. C

    It marks all lost sinks as "taint propagators".

  4. D

    It marks all lost sources as "taint propagators".

Show answer and explanation

Correct answer: C

Question 2 Single choice

Your customer is a small-sized development company. They would like AppScan Source to be used by a security team of 2 people and a development team of 6 people.

Which server license would be recommended for this organization?

  1. A

    AppScan Enterprise Server

  2. B

    AppScan Source Server Core

  3. C

    AppScan Source for Automation

  4. D

    AppScan Enterprise Server Basic

Show answer and explanation

Correct answer: A

Question 3 Multiple choice

Which two methods can be used to resolve Unresolved Include Expressions?

  1. A

    Adding additional Scan Rules

  2. B

    Adding additional search and replace rules

  3. C

    Adding additional PHP Document Roots to the project

  4. D

    Adding additional source files in the project properties menu

  5. E

    Adding additional directories that contain PHP include files to the include path

Show answer and explanation

Correct answers: C, E

Question 4 Single choice

In AppScan Source for Analysis, you are configuring a Java web application that contains JSPs. The following is a directory tree for your application:

On the JSP Project Dependencies tab.
which folder should be selected as the 'Web Context Root'?

  1. A

    Java

  2. B

    scripts

  3. C

    webapp

  4. D

    resources

Show answer and explanation

Correct answer: A

Question 5 Single choice

How does the "Single virtual call" setting affect scan behavior?

  1. A

    If set to true, it allows the detection of all virtual functions calls.

  2. B

    If set to false, it allows the detection of all virtual functions calls.

  3. C

    If set to true, it allows the taint analysis to follow multiple implementations of a virtual function.

  4. D

    If set to false, it allows the taint analysis to follow multiple implementations of a virtual function.

Show answer and explanation

Correct answer: B

Question 6 Single choice

What is the best practice for scanning an Android application?

  1. A

    Import Workspace, Scan Application

  2. B

    Install Eclipse IDE, Scan Application

  3. C

    Add JAVA files manually, Add Dependencies. Scan Application

  4. D

    Verify build succeeds in Eclipse. Import Workspace, Scan Application

Show answer and explanation

Correct answer: C

Question 7 Multiple choice

Where are two places you can open a saved bundle?

  1. A

    AppScan Standard

  2. B

    AppScan Enterprise Server

  3. C

    AppScan Source for Analysis

  4. D

    AppScan Source for Automation

  5. E

    AppScan Source for Development

Show answer and explanation

Correct answers: C, E

Question 8 Single choice

You are reviewing a banking application and find a lost sink method called performTransactionf...) that sends requested transaction information (bill payment, funds transfer, etc) to the back-end COBOL application running on IBM System z mainframe that actually moves the money.

Which type of custom rule should you create for this method?

  1. A

    Sink

  2. B

    Source

  3. C

    Taint Propagator

  4. D

    Tainted Callback

  5. E

    Not Susceptible to taint

Show answer and explanation

Correct answer: D

Question 9 Multiple choice

Reports in AppScan Source Edition can be exported in which two formats?

  1. A

    pdf

  2. B

    xml

  3. C

    html

  4. D

    Microsoft Excel

  5. E

    Microsoft Word

Show answer and explanation

Correct answers: A, B

Question 10 Single choice

Which AppScan component is required to create PBSA rules?

  1. A

    AppScan Source for Analysis

  2. B

    AppScan Source for Automation

  3. C

    AppScan Source for Remediation

  4. D

    AppScan Source for Development

Show answer and explanation

Correct answer: D