Exam Code: C2150-810 (Practice Exam Latest Test Questions VCE PDF)
Exam Name: IBM Security AppScan Source Edition Implementation
Certification Provider: IBM
Free Today! Guaranteed Training- Pass C2150-810 Exam.

2021 May C2150-810 Study Guide Questions:

Q11. What is the difference between AppScan Source Developer and AppScan Source Remediation licenses? 

A. AppScan Source for Remediation supports only Visual Studio while AppScan Source for Developer supports both Eclipse and Visual Studio. 

B. AppScan Source Developer allows you to run scans from CLI, while AppScan Source Remediation allows you only to remediate security issues. 

C. AppScan Source Developer allows you only to remediate security issues, while AppScan Source Remediation allows you to run scans from within the IDE. 

D. AppScan Source Developer allows you to run scans from within the IDE, while AppScan Source Remediation allows you only to remediate security issues. 

Answer: A 


Q12. You are reviewing an application and discover a method called doSomethingQ that retrieves and returns data from another system. 

Which type of custom rule do you need to create for AppScan Source to properly capture this data? 

A. Sink 

B. Source 

C. Taint Propagator 

D. Tainted Callback 

E. Not Susceptible to Taint 

Answer: D 


Q13. Which two methods can be used to resolve Unresolved Include Expressions? 

A. Adding additional Scan Rules 

B. Adding additional search and replace rules 

C. Adding additional PHP Document Roots to the project 

D. Adding additional source files in the project properties menu 

E. Adding additional directories that contain PHP include files to the include path 

Answer: C,E 


certifyforall.com

Improve C2150-810 torrent:

Q14. What are bundles in IBM Security AppScan Source? 

A. Bundles are groups of filters created in AppScan Source for Analysis. 

B. Bundles are groups of reports created in AppScan Source for Analysis. 

C. Bundles are groups of findings created in AppScan Source for Analysis. 

D. Bundles are groups of findings created in AppScan Enterprise Server and imported to AppScan Source for Analysis. 

Answer: C 


Q15. Which two AppScan Source components can be used to generate reports? 

A. AppScan Source for Core 

B. AppScan Source for Analysis 

C. AppScan Source for Developer 

D. AppScan Source for Automation 

E. AppScan Source for Remediation 

Answer: C,D 


Q16. You are reviewing an online shopping application and find a lost sink method called combineltemListsf..,) that is provided by a third-party shopping framework. This method combines two lists of items (provided as arguments) into one. 

Which type of custom rule do you need to create for this method? 

A. Sink 

B. Source 

C. Taint Propagator 

D. Tainted Callback 

E. Not Susceptible to Taint 

Answer: C 

Reference:http://pic.dhe.ibm.com/infocenter/appsrc/v8r5/index.jsp?topic=%2Fcom.ibm.ratio nal.appscansrc.security.doc%2Ftopics%2Fcustomizing_the_db_rules_wizard.html 


C2150-810  test

100% Guarantee C2150-810 discount pack:

Q17. You are reviewing an application and come across a method called doSomething() that can be executed by other systems to provide data to the application via this method's 

parameters. 

Which type of custom rule do you need to create for AppScan Source to properly capture this data? 

A. Sink 

B. Source 

C. Taint Propagator 

D. Tainted Callback 

E. Not Susceptible to Taint 

Answer: B 


Q18. How are safe sources dismissed during the triage process? 

A. Set all the sinks originated from the safe source to NST. 

B. Set a Trace filter to remove any findings that originated from the safe source. 

C. Set a Classification filter to remove any findings that originated from the safe source. 

D. Set a Vulnerability Type filter to remove any findings that originated from the safe source. 

Answer: D 


Q19. Which two components are required to install AppScan Enterprise Server with reporting? 

A. DB2 

B. AppScan Standard 

C. Microsoft SQL Server 

D. Team Foundation Server 

E. Internet Information Services 

Answer: A,B 


Q20. You are reviewing a banking application and find a lost sink method called performTransactionf...) that sends requested transaction information (bill payment, fundstransfer, etc) to the back-end COBOL application running on IBM System z mainframe that actually moves the money. 

Which type of custom rule should you create for this method? 

A. Sink 

B. Source 

C. Taint Propagator 

D. Tainted Callback 

E. Not Susceptible to taint 

Answer: D