HP Assessing Web Application Security Sample Questions:
1. Which statements about WebInspect Macros are true? Select two.
A) The Start Macro runs only once at the start of the assessment.
B) The Start Macro is used to gain session state at the beginning of the assessment and to
maintain session state throughout.
C) The Login Macro runs only once at the start of the assessment.
D) The Logout Macro is used to maintain session state throughout the assessment.
E) The Login Macro is used to maintain session state throughout the assessment.
2. What is one way to determine what made a vulnerability flag in Webinspect?
A) Right-click the vulnerability and View Detailed Response.
B) Highlight the vulnerability in Summary Pane and read the recommended remediations.
C) Note the highlighted text appearing in the HTTP Response View.
D) Analyze the HTTP Request to see what type of parameter manipulation was performed.
3. How do you initiate the WebInspect Command Line?
A) via the Advanced Assessment panel
B) via the scheduler.exe program
C) via the WebInspect toolkit
D) via the wi.exe program
4. How is the Match setting in the definition of a web form value used?
A) The Match setting for a Web Form parameter qualifies the entry using the criteria; "Exact", "Close" or "Close Enough".
B) The Match setting for a Web Form parameter qualifies the entry using the criteria; "Exact", "Starts With" or "Contains".
C) The Match setting for a Web Form parameter resolves conflicts between web macro parameters and Web Form Values parameters.
D) The Match setting for a Web Form parameter forces exact matches only of form names.
5. Which statement best describes SmartUpdate?
A) SmartUpdate is a process that retrieves updates to the local vulnerability database and any WebInspect binary updates.
B) SmartUpdate is the feature that sends False Positives (FP) to the HP Support team as quality feedback.
C) SmartUpdate is the process that delivers WebInspect Messages to the bottom of the Home tab.
D) SmartUpdate automatically omits security checks whose specified server/application type does not match the current targets server/application fingerprint.
Solutions:
| Question # 1 Answer: A,E | Question # 2 Answer: C | Question # 3 Answer: D | Question # 4 Answer: B | Question # 5 Answer: A |
We're so confident of our products that we provide no hassle product exchange.


By Berger

