IBM Security AppScan Source Edition Implementation - C2150-810 Exam Practice Test

Question 1
You are reviewing a thick client application and come upon File Injection findings in a function that opens zip files and extracts data from them, but the customer you are working with tells you that the data is sanitized using a method mySanitizer.validateZip{..). You confirm this and decide to remove this vulnerability and other File injection findings with sanitized data using the Remove functionality of the Trace section in the Filter Editor.
In which area of the Trace Rule Entry dialog would you add mySanitizer.validateZip(..) method?

Correct Answer: D
Question 2
You are scanning a thick client application that receives data over a custom TCP/IP protocol provided by the application's framework method AppComm.getReceivedMessage().
Which rule would you create for this method to capture and trace the incoming data?

Correct Answer: C
Question 3
To scan JavaScript included within an ASP.NET application, which additional steps must be completed to ensure these artifacts are scanned?

Correct Answer: A
Question 4
Which two licenses can be used for AppScan Source IDE plug-ins?

Correct Answer: B,E
Question 5
How can a user be prevented from creating new custom rules?

Correct Answer: B