Exam Code: C2150-810 (Practice Exam Latest Test Questions VCE PDF)
Exam Name: IBM Security AppScan Source Edition Implementation
Certification Provider: IBM
Free Today! Guaranteed Training- Pass C2150-810 Exam.
2021 Apr C2150-810 Study Guide Questions:
Q1. When scanning a PHP application, what will occur if the PHP Document Root was not specified?
A. The source root that was specified in the Project Sources page will be used instead.
B. The scan proceeds with scanning zero source files and will thus produce zero findings.
C. The scan will immediately fail with an error asking the user to re-run the creation wizard.
D. The scan will only produce scan rule or PBSA (pattern based semantic analysis) findings.
Answer: A
Reference:http://pic.dhe.ibm.com/infocenter/appsrc/v8r6/index.jsp?topic=%2Fcom.ibm.ratio nal.appscansrc.security.doc%2Ftopics%2Fsetting_up_add_project_php.html
Q2. What is the best practice for scanning an Android application?
A. Import Workspace, Scan Application
B. Install Eclipse IDE, Scan Application
C. Add JAVA files manually, Add Dependencies. Scan Application
D. Verify build succeeds in Eclipse. Import Workspace, Scan Application
Answer: C
Q3. Your customer is a small-sized development company. They would like AppScan Source to be used by a security team of 2 people and a development team of 6 people.
Which server license would be recommended for this organization?
A. AppScan Enterprise Server
B. AppScan Source Server Core
C. AppScan Source for Automation
D. AppScan Enterprise Server Basic
Answer: A

Replace C2150-810 practice exam:
Q4. In order to publish Assessments to AppScan Enterprise Console for the first time, which settings must be configured?
A. InAppScan Source settings, in the Application Server preference page
B. InAppScan Enterprise Server settings, in the Jazz Team Server preference page
C. InAppScan Source settings, in the AppScan Enterprise Console preference page
D. InAppScan Enterprise Server settings, in the Microsoft SQL server preference page
Answer: C
Reference:http://pic.dhe.ibm.com/infocenter/appsrc/v8r6/index.jsp?topic=%2Fcom.ibm.ratio nal.appscansrc.security.doc%2Ftopics%2Fmanaging_assessments_ase_integration.html( Second para aobut this task ).
Q5. You want to scan and bundle the results for a Java application and only have access to one machine. Which two components must be installed on that machine to execute a scan and bundle the results?
A. AppScan Enterprise Server
B. AppScan Source for Analysis
C. AppScan Source for Automation
D. AppScan Source for Remediation
E. AppScan Source for Development
Answer: B,E
Q6. Your customer wants to implement AppScan Source for a small security experts group: two researchers who will be using the tool in their daily routine, often at the same time.
Which licenses would you recommend for purchase?
A. 1 AppScan Enterprise Server and 1 AppScan Source for Analysis floating user licenses
B. 2 AppScan Enterprise Server Basic and 1 AppScan Source for Analysis floating user licenses
C. 1 AppScan Enterprise Server Basic and 2 AppScan Source for Analysis authorized user licenses
D. 2 AppScan Enterprise Server Basic and 2 AppScan Source for Analysis authorized user licenses
Answer: C

Free C2150-810 guidance:
Q7. You are reviewing an on-line shopping application and find a lost sink method called retrieveOrderf...) that is provided by a third party shopping framework. This method accepts order number and in turn provides all information regarding that order such as items ordered, shipping and billing address, payment type, etc .
Which type of custom rule should you create for this method?
A. Sink
B. Source
C. Taint Propagator
D. Tainted Callback
E. Not Susceptible to Taint
Answer: B
Q8. You are reviewing an on-line shopping application and find a lost sink method called generateltemNotFoundMessage() provided by a third-party shopping framework. This method returns a search string that was passed in. prepended with an "item not found" message in English, French or Spanish (depending on user's selection).
Which type of custom rule do you need to create for this method?
A. Sink
B. Source
C. Taint Propagator
D. Tainted Callback
E. Not Susceptible to Taint
Answer: B
Q9. Which task allows users to specify a Web Context Root for each generated project using Ounce/Ant?
A. ounceCli
B. ounceCreateProject
C. ounce.project_name
D. ounce.build.compiler
Answer: B
Reference:https://www-01.ibm.com/support/knowledgecenter/SSS9LM_9.0.0/com.ibm.rational.appscansrc.utilities. doc/topics/ounce_ant_integration_properties_setting.html?lang=en
Q10. Which statement is true about AppScan Source's defect tracking system integration?
A. It can be used to submit one or more findings in a single defect entry.
B. It can be used to submit one or more bundles in a single defect entry.
C. It can be used to update finding status in AppScan Source from a defect entry.
D. It can be used to submit defects during unattended scans using AppScan Source for Automation.
Answer: B
Reference:http://pic.dhe.ibm.com/infocenter/appsrc/v8r6/index.jsp