Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Certified AppSec Practitioner Exam Practice Questions

Exams4sure Dumps

Exam style questions across every CAP domain

Last Update 4 days ago
Total Questions : 60

Start with our free CAP practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real AppSec Practitioner exam. Each CAP exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your The SecOps Group weak domains, see where you're losing marks, and build a focused study plan in minutes.

CAP PDF

CAP PDF (Printable)
$46.5
$154.99

CAP Testing Engine

CAP PDF (Printable)
$51
$169.99

CAP PDF + Testing Engine

CAP PDF (Printable)
$63.9
$212.99
Question # 11

Which is the most effective way of input validation to prevent Cross-Site Scripting attacks?

Options:

A.  

Blacklisting HTML and other harmful characters

B.  

Whitelisting and allowing only trusted input

C.  

Using a Web Application Firewall (WAF)

D.  

Marking Cookie as HttpOnly

Discussion 0
Question # 12

In the context of the CORS (Cross-origin resource sharing) misconfiguration, which of the following statements is true?

Options:

A.  

CORS is exploitable if the value of the HTTP headers are Access-Control-Allow-Origin: * and Access-Control-Allow-Credentials: true

B.  

CORS is exploitable if the value of the HTTP headers are Access-Control-Allow-Origin: * and Access-Control-Allow-Credentials: false

C.  

CORS is exploitable if the value of the HTTP headers is Access-Control-Allow-Origin: * and the value of the Access-Control-Allow-Credentials header is irrelevant

D.  

All of the above

Discussion 0
Question # 13

In the screenshot below, which of the following is incorrect?

Target: https://example.com

HTTP/1.1 404 Not Found

Date: Fri, 09 Dec 2022 18:03:49 GMT

Server: Apache

Vary: Cookie

X-Powered-By: PHP/5.4.5-5

X-Xss-Protection: 1; mode=block

X-Content-Type-Options: nosniff

Content-Length: 0

Content-Type: text/html; charset=UTF-8

Cookie: JSESSIONID=1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789; secure; HttpOnly; SameSite=None

Options:

A.  

The application discloses the framework name and version

B.  

The application reveals user-agent details

C.  

A cookie is set with HttpOnly and a Secure flag

D.  

The application accepts insecure protocol

Discussion 0
Question # 14

Null Byte Injection is an active exploitation technique used to bypass sanity-checking filters in web applications by adding a URL-encoded null byte character to the user-supplied data. Which of the following is a URL-encoded representation of a null byte?

Options:

A.  

%01

B.  

%10

C.  

%25

D.  

%00

Discussion 0
Question # 15

Which of the following SSL/TLS protocols are considered to be insecure?

Options:

A.  

SSLv2 and SSLv3

B.  

TLSv1.0 and TLSv1.1

C.  

Both A and B

D.  

SSLv2, SSLv3, TLSv1.0, TLSv1.1, TLSv1.2 and TLSv1.3

Discussion 0
Question # 16

GraphQL is an open-source data query and manipulation language for APIs, and a query runtime engine. In this context, what is GraphQL Introspection?

Options:

A.  

A technique for testing the compatibility of the GraphQL API with other systems

B.  

A technique for testing the performance of the GraphQL API

C.  

A technique for discovering the structure of the GraphQL API

D.  

A technique for testing the security of the GraphQL API

Discussion 0
Question # 17

Salt is a cryptographically secure random string that is added to a password before it is hashed. In this context, what is the primary objective of salting?

Options:

A.  

To defend against dictionary attacks or attacks against hashed passwords using a rainbow table.

B.  

To slow down the hash calculation process.

C.  

To generate a long password hash that is difficult to crack.

D.  

To add a secret message to the password hash.

Discussion 0
Question # 18

An application’s forget password functionality is described below:

The user enters their email address and receives a message on the web page:

“If the email exists, we will email you a link to reset the password”

The user also receives an email saying:

“Please use the link below to create a new password:”

(Note that the developer has included a one-time random token with the ‘userId’ parameter in the link). So, the link seems like:

https://example.com/reset_password?userId=5298 &token=70e7803e-bf53-45e1-8a3f-fb15da7de3a0

Will this mechanism prevent an attacker from resetting arbitrary users’ passwords?

Options:

A.  

True

B.  

False

Discussion 0

Free Exams Sample Questions