Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Certified AppSec Practitioner Exam Practice Questions

Exams4sure Dumps

Exam style questions across every CAP domain

Last Update 4 days ago
Total Questions : 60

Start with our free CAP practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real AppSec Practitioner exam. Each CAP exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your The SecOps Group weak domains, see where you're losing marks, and build a focused study plan in minutes.

CAP PDF

CAP PDF (Printable)
$46.5
$154.99

CAP Testing Engine

CAP PDF (Printable)
$51
$169.99

CAP PDF + Testing Engine

CAP PDF (Printable)
$63.9
$212.99
Question # 1

In the screenshot below, an attacker is attempting to exploit which vulnerability?

POST /dashboard HTTP/1.1

Host: example.com

User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) rv:107.0) Gecko/20100101 Firefox/107.0

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8

Accept-Language: en-GB,en;q=0.5

Accept-Encoding: gzip, deflate

Upgrade-Insecure-Requests: 1

Sec-Fetch-Dest: document

Sec-Fetch-Mode: navigate

Sec-Fetch-Site: none

Sec-Fetch-User: ?1

Cookie: JSESSIONID=7576572ce164646de967c759643d53031

Te: trailers

Connection: keep-alive

Content-Type: application/x-www-form-urlencoded

Content-Length: 81

xml_foo=]>&example;

]>&example;

&example;

Project Meeting

changed example

Options:

A.  

Path Traversal Attack

B.  

Server Side Template Injection

C.  

XML Bomb Attack

D.  

XML External Entity Attack

Discussion 0
Question # 2

What is the full form of SAML?

Options:

A.  

Security Assertion Markup Language

B.  

Security Authorization Markup Language

C.  

Security Assertion Management Language

D.  

Secure Authentication Markup Language

Discussion 0
Question # 3

The following request is vulnerable to Cross-Site Request Forgery vulnerability.

POST /changepassword HTTP/2Host: example.com User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) rv:107.0) Gecko/20100101 Firefox/107.0 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: same-origin Cookie: JSESSIONID=38RC5ECV10785B53AF19816E92E2E50 Content-Length: 95

new_password=lov3MyPiano23&confirm_password=lov3MyPiano23

Options:

A.  

True

B.  

False

Discussion 0
Question # 4

Based on the screenshot below, which of the following statements is true?

Request

GET /userProfile.php?sessionId=7576572ce164646de967c759643d53031 HTTP/1.1

Host: example.com

User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) Firefox/107.0

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8

Accept-Language: en-GB,en;q=0.5

Accept-Encoding: gzip, deflate

Upgrade-Insecure-Requests: 1

Sec-Fetch-Dest: document

Sec-Fetch-Mode: navigate

Sec-Fetch-Site: none

Sec-Fetch-User: ?1

Cookie: JSESSIONID=7576572ce164646de967c759643d53031

Te: trailers

Connection: keep-alive

PrettyRaw | Hex | php | curl | ln | Pretty

HTTP/1.1 200 OK

Date: Fri, 09 Dec 2022 11:42:27 GMT

Server: Apache/2.4.54 (Unix) OpenSSL/1.0.2k-fips PHP/8.0.25

X-Powered-By: PHP/8.0.25

Content-Length: 12746

Content-Type: text/html; charset=UTF-8

Connection: keep-alive

Set-Cookie: JSESSIONID=7576572ce164646de967c759643d53031; Path=/; HttpOnly

Example Domain

...

Options:

A.  

The application uses an insecure channel (non-TLS)

B.  

The application uses an insecure HTTP method (GET) to send sensitive information

C.  

The application is vulnerable to Cross-Site Scripting attacks

D.  

All of the above

Discussion 0
Question # 5

Multifactor authentication will NOT be able to prevent:

Options:

A.  

Cross-Site Scripting Vulnerability

B.  

Cross-Site Request Forgery Vulnerability

C.  

Path Traversal Vulnerability

D.  

All of the above

Discussion 0
Question # 6

What is the name of the WordPress file that contains the database connection information, including the database name, username, and password?

Options:

A.  

wp-configuration.php

B.  

wp-conf.php

C.  

wp-secret.php

D.  

wp-config.php

Discussion 0
Question # 7

In the context of the Race Condition vulnerability, which of the following statements is true?

Options:

A.  

A situation that occurs when two threads access the same resource at the same time.

B.  

A situation that occurs when two threads access different resources at the same time.

C.  

A situation that occurs when a single thread unpredictably accesses two resources.

D.  

A situation that occurs when a single thread predictably accesses two resources.

Discussion 0
Question # 8

A website administrator forgot to renew the TLS certificate on time and as a result, the application is now displaying a TLS error message. However, on closer inspection, it appears that the error is due to the TLS certificate expiry.

In the scenario described above, which of the following is correct?

Options:

A.  

There is no urgency to renew the certificate as the communication is still over TLS

B.  

There is an urgency to renew the certificate as the users of the website may get conditioned to ignore TLS warnings and therefore ignore a legitimate warning which could be a real Man-in-the-Middle attack

Discussion 0
Question # 9

Which of the following hashing algorithms is considered to be the most secure amongst these?

Options:

A.  

SHA-0

B.  

MD5

C.  

SHA-1

D.  

Bcrypt

Discussion 0
Question # 10

After purchasing an item on an e-commerce website, a user can view his order details by visiting the URL:

https://example.com/order_id=53870

A security researcher pointed out that by manipulating the order_id value in the URL, a user can view arbitrary orders and sensitive information associated with that order_id.

Which of the following is correct?

Options:

A.  

The root cause of the problem is a lack of input validation and by implementing a strong whitelisting, the problem can be solved

B.  

The root cause of the problem is a weak authorization (Session Management) and by validating a user's privileges, the issue can be fixed

C.  

The problem can be solved by implementing a Web Application Firewall (WAF)

D.  

None of the above

Discussion 0

Free Exams Sample Questions