|
IBM 000-M24 Exam - CertifySky.com Free 000-M24 Sample Questions:
Q: 1 What happens when AppScan generates an Industry Standard report?
A. It maps the discovered vulnerabilities to a set of industry-specific checkpoints.
B. It generates and executes industry-specific tests.
C. It provides industry-specific advisories.
D. It applies an industry-specific test policy.
Answer: A
Q: 2 How can you specify what information is included in an AppScan report?
A. By specifying particular tests
B. By selecting / deselecting individual items of information
C. By exploring manually
D. By creating custom tests
Answer: B
Q: 3 Which AppScan user interface provides relevant information about how
AppScan tests for a particular vulnerability?
A. Application Tree
B. Request / Response
C. Advisory
D. Application Data
E. Remediation Tasks View
F. Security Issues View
Answer: B
Q: 4 Which AppScan feature is used to verify that AppScan is still logged in to the
application during scanning?
A. In-session detection
B. Manual Explore
C. Automatic Explore
D. Automatic Form Fill
Answer: A
Q: 5 What information does the 'Difference' displayed in the Request / Response
tab provide?
A. The difference between two tests
B. How AppScan constructed the test HTTP request
C. How the vulnerability was resolved
D. How the web application page has been modified from its previous version
Answer: B
Q: 6 What does AppScan do when the user selects the Automatic Explore option?
A. Performs delta analysis automatically
B. Tests automatically for privilege escalation vulnerabilities
C. Follows all web application links automatically
D. Generates an OWASP top 10 report automatically
Answer: C
Q: 7 Which is not a use case for Manual Explore?
A. Scan specific pages
B. Execute specific tests
C. Navigate through complex sites
D. Follow a particular functional path
Answer: B
Q: 8 Which feature does AppScan provide that takes the user through the steps
for creating a new scan?
A. A wizard
B. A workflow
C. A policy
D. A report
Answer: A
Q: 9 How does Web Services Explorer use the web service WSDL file?
A. Generates the necessary security tests
B. Builds a simple UI so that the user can interact with the web service
C. Generates a security report
D. Authenticates AppScan to the Web Application
Answer: B
Q: 10 Which type of information does the Fix Recommendation tab contain?
A. Code samples
B. Vulnerability description
C. Regulatory compliance information
D. Description of the executed test
Answer: A |