IBM C2150-810 Exam Overview:
| Certification Vendor: | IBM |
| Exam Name: | IBM Security AppScan Source Edition Implementation C2150-810 |
| Exam Number: | C2150-810 |
| Available Languages: | English |
| Sample Questions: | IBM C2150-810 Sample Questions |
IBM C2150-810 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| AppScan Source Overview | - Product architecture and components - Security testing concepts and workflow |
| Reporting and Integration | - Integration with development tools and CI/CD pipelines - Generating security reports |
| Application Scanning | - Source code import and analysis process - Static analysis scan configuration |
| Vulnerability Analysis and Remediation | - Fix recommendations and validation - Interpreting scan results |
| Installation and Configuration | - Environment setup and prerequisites - Client and server configuration |
IBM Security AppScan Source Edition Implementation Sample Questions:
1. You are reviewing a cloud storage locker application that is used to store and share user files and backups. You come across Cross-Site Scripting findings with data coming from several different sources. The customer you are working with is just getting started and is looking for highest priority issues only, so you need to focus on those issues that originate from the source that poses the highest risk.
Which source poses the highest risk?
A) TCPNetworkHandler.getByteArray()
B) ZipCrypto.extract()
C) ConfigXMLgetConfigValue()
D) FileUpload.getFileContents()
E) SqIDB.getValueO
2. What is the proper action to take if the attack surface proves to be insufficient?
A) Make sure scan configuration for single virtual call is set to true
B) Perform application profiling to identify any missing sources
C) Remove all the filters to maximize the findings
D) Clear any findings from the excluded bundle
3. In AppScan Source for Analysis, you are configuring a Java web application that contains JSPs. The following is a directory tree for your application:
On the JSP Project Dependencies tab. which folder should be selected as the 'Web Context Root'?
A) Java
B) webapp
C) scripts
D) resources
4. Reports in AppScan Source Edition can be exported in which two formats?
A) xml
B) Microsoft Word
C) html
D) Microsoft Excel
E) pdf
5. You are reviewing an online shopping application and find a lost sink method called combineltemListsf..,) that is provided by a third-party shopping framework. This method combines two lists of items (provided as arguments) into one.
Which type of custom rule do you need to create for this method?
A) Tainted Callback
B) Taint Propagator
C) Sink
D) Not Susceptible to Taint
E) Source
Solutions:
| Question # 1 Answer: D | Question # 2 Answer: C | Question # 3 Answer: A | Question # 4 Answer: A,E | Question # 5 Answer: B |
We're so confident of our products that we provide no hassle product exchange.


By Archibald

