Weekend Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

Ace Your 312-96 Application Security Exam

Page: 2 / 3
Question 8

In a certain website, a secure login feature is designed to prevent brute-force attack by implementing account lockout mechanism. The account will automatically be locked after five failed attempts. This feature will not allow the users to login to the website until their account is unlocked. However, there is a possibility that this security feature can be abused to perform __________ attack.

Options:

A.

Failure to Restrict URL

B.

Broken Authentication

C.

Unvalidated Redirects and Forwards

D.

Denial-of-Service [Do

Question 9

To enable the struts validator on an application, which configuration setting should be applied in the struts validator configuration file?

Options:

A.

valid ate-'true"

B.

lsNotvalidate="disabled"

C.

lsNotvalidate="false"

D.

validate="enabled"

Question 10

The threat modeling phase where applications are decomposed and their entry points are reviewed from an attacker's perspective is known as ________

Options:

A.

Attack Surface Evaluation

B.

Threat Classification

C.

Threat Identification

D.

Impact Analysis

Question 11

Identify the type of attack depicted in the figure below:

Options:

A.

XSS

B.

Cross-Site Request Forgery (CSRF) attack

C.

SQL injection attack

D.

Denial-of-Service attack

Page: 2 / 3
Ace Your 312-96 Application Security Exam, Last Attempt 312-96 Questions,
Exam Code: 312-96
Exam Name: Certified Application Security Engineer (CASE) JAVA
Last Update: May 18, 2024
Questions: 47
312-96 pdf

312-96 PDF

$28  $80
312-96 Engine

312-96 Testing Engine

$33.25  $95
312-96 PDF + Engine

312-96 PDF + Testing Engine

$45.5  $130