Study HIGH Quality 312-96 Free Study Guides and Exams Tutorials
Download ECCouncil 312-96 Exam Dumps to Pass Exam Easily
NEW QUESTION # 13
Oliver, a Server Administrator (Tomcat), has set configuration in web.xml file as shown in the following screenshot. What is he trying to achieve?
- A. He wants to transfer only response parameter data over encrypted channel
- B. He wants to transfer only Session cookies over encrypted channel
- C. He wants to transfer only request parameter data over encrypted channel
- D. He wants to transfer the entire data over encrypted channel
Answer: D
NEW QUESTION # 14
Identify the type of encryption depicted in the following figure.
- A. Symmetric Encryption
- B. Hashing
- C. Asymmetric Encryption
- D. Digital Signature
Answer: A
NEW QUESTION # 15
Alice, a security engineer, was performing security testing on the application. He found that users can view the website structure and file names. As per the standard security practices, this can pose a serious security risk as attackers can access hidden script files in your directory. Which of the following will mitigate the above security risk?
- A. < int-param > < param-name>listinqs < param-value>true < /init-param
- B. < int param > < param-name>directorv-listinqs < param-value>false < /init-param >
- C. < int-param > < param-name>directory-listinqs < param-value>true < /init-param >
- D. < int-param > < param-name>listinqs < param-value>false < /init-param >
Answer: B
NEW QUESTION # 16
Which line of the following example of Java Code can make application vulnerable to a session attack?
- A. Line No. 4
- B. Line No. 5
- C. Line No. 1
- D. Line No. 3
Answer: D
NEW QUESTION # 17
Sam, an application security engineer working in INFRA INC., was conducting a secure code review on an application developed in Jav a. He found that the developer has used a piece of code as shown in the following screenshot. Identify the security mistakes that the developer has coded?
- A. He is attempting to use whitelist input validation approach
- B. He is attempting to use regular expression for validation
- C. He is attempting to use client-side validation
- D. He is attempting to use blacklist input validation approach
Answer: D
NEW QUESTION # 18
Jacob, a Security Engineer of the testing team, was inspecting the source code to find security vulnerabilities.
Which type of security assessment activity Jacob is currently performing?
- A. ISCST
- B. CAST
- C. SAST
- D. CAST
Answer: C
NEW QUESTION # 19
Which of the following can be derived from abuse cases to elicit security requirements for software system?
- A. Use cases
- B. Security use cases
- C. Data flow diagram
- D. Misuse cases
Answer: B
NEW QUESTION # 20
Identify the type of attack depicted in the following figure.
- A. Denial-of-Service Attack
- B. SQL Injection Attacks
- C. Session Fixation Attack
- D. Parameter Tampering Attack
Answer: D
NEW QUESTION # 21
Alice works as a Java developer in Fygo software Services Ltd. He is given the responsibility to design a bookstore website for one of their clients. This website is supposed to store articles in .pdf format. Alice is advised by his superior to design ArticlesList.jsp page in such a way that it should display a list of all the articles in one page and should send a selected filename as a query string to redirect users to articledetails.jsp page.
Alice wrote the following code on page load to read the file name.
String myfilename = request.getParameter("filename");
String txtFileNameVariable = myfilename;
String locationVariable = request.getServletContext().getRealPath("/"); String PathVariable = ""; PathVariable = locationVariable + txtFileNameVariable; BufferedInputStream bufferedInputStream = null; Path filepath = Paths.get(PathVariable); After reviewing this code, his superior pointed out the security mistake in the code and instructed him not repeat the same in future. Can you point the type of vulnerability that may exist in the above code?
- A. URL Tampering vulnerability
- B. XSS vulnerability
- C. Form Tampering vulnerability
- D. Directory Traversal vulnerability
Answer: D
NEW QUESTION # 22
According to secure logging practices, programmers should ensure that logging processes are not disrupted by:
- A. Throwing incorrect exceptions
- B. Multiple catching of incorrect exceptions
- C. Catching incorrect exceptions
- D. Re-throwing incorrect exceptions
Answer: A
NEW QUESTION # 23
The developer wants to remove the HttpSessionobject and its values from the client' system.
Which of the following method should he use for the above purpose?
- A. isValidateQ
- B. invalidateQ
- C. sessionlnvalidateil
- D. Invalidate(session JSESSIONID)
Answer: B
NEW QUESTION # 24
Which of the following is used to mapCustom Exceptions to Statuscode?
- A. @ResponseCode
- B. @ResponseStatus
- C. @ResponseStatusCode
- D. @ScacusCode
Answer: B
NEW QUESTION # 25
It is recommended that you should not use return, break, continue or throw statements in _________
- A. Try-With-Resources block
- B. Finally block
- C. Try block
- D. Catch block
Answer: B
NEW QUESTION # 26
Which of the following state management method works only for a sequence of dynamically generated forms?
- A. Sessions
- B. Hidden Field
- C. Cookies
- D. URL-rewriting
Answer: B
NEW QUESTION # 27
A developer has written the following line of code to handle and maintain session in the application. What did he do in the below scenario?
- A. Maintained session by creating a Cookie user with value stored in uname variable.
- B. Maintained session by creating a hidden variable user with value stored in uname variable.
- C. Maintained session by creating a HTTP variable user with value stored in uname variable.
- D. Maintained session by creating a Session variable user with value stored in uname variable.
Answer: D
NEW QUESTION # 28
Which of the following DFD component is used to represent the change in privilege levels?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION # 29
In which phase of secure development lifecycle the threat modeling is performed?
- A. Coding phase
- B. Testing phase
- C. Design phase
- D. Deployment phase
Answer: C
NEW QUESTION # 30
......
Get 100% Real Free Application Security 312-96 Sample Questions: https://vcetorrent.passreview.com/312-96-exam-questions.html