HP Assessing Web Application Security Sample Questions:
1. What is one way to determine the GUID, or scan name, associated with a particular scan?
A) Open the Scan and look at the Scan Properties.
B) Open the Scan and look at Scan ID in Scan Log .
C) Run the Scan Statistics report on the scan.
D) Find the folder where scan data is stored and find the correct scan file.
2. What is the purpose of the setting "Enable Active Content in Browser Views"?
A) It permits the user to make live requests and view their responses within the Step-Mode pane.
B) It permits WebInspect to make live requests against the target server during an assessment.
C) It permits the MSIE Helper object to load ActiveX during an assessment.
D) It permits the execution of Javascript and other dynamic content within the WebInspect
GUI.
3. When evaluating a vulnerability within the WebInspect GUI, where would you find a full description of the vulnerability, including recommended remediation steps?
A) Report -> QA Summary option
B) Summary Pane -> Information tab
C) Summary Pane -> Server Information tab
D) Information Pane -> Vulnerability view
4. How is the Match setting in the definition of a web form value used?
A) The Match setting for a Web Form parameter resolves conflicts between web macro parameters and Web Form Values parameters.
B) The Match setting for a Web Form parameter qualifies the entry using the criteria; "Exact", "Starts With" or "Contains".
C) The Match setting for a Web Form parameter qualifies the entry using the criteria; "Exact", "Close" or "Close Enough".
D) The Match setting for a Web Form parameter forces exact matches only of form names.
5. After determining that a vulnerability finding is a False Positive, how do you mark the
vulnerability as a False Positive?
A) Right click vulnerability -> select Ignore Vulnerability -> Mark as False Positive
B) Right click vulnerability -> select Edit Vulnerability -> Mark as False Positive
C) Right click vulnerability -> select Change Vulnerability Severity -> Mark as False Positive
D) Right click vulnerability -> select Annotate -> Mark as False Positive
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: D | Question # 3 Answer: D | Question # 4 Answer: B | Question # 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Clyde

