Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Certified AppSec Practitioner Exam

Last Update 15 hours ago Total Questions : 60

The Certified AppSec Practitioner Exam content is now fully updated, with all current exam questions added 15 hours ago. Deciding to include CAP practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CAP exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CAP sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Certified AppSec Practitioner Exam practice test comfortably within the allotted time.

Question # 11

Which of the following security attributes ensures that the browser only sends the cookie over a TLS (encrypted) channel?

A.

Secure

B.

HttpOnly

C.

No_XSS

D.

None of the above

Question # 12

What is the name of the WordPress file that contains the database connection information, including the database name, username, and password?

A.

wp-configuration.php

B.

wp-conf.php

C.

wp-secret.php

D.

wp-config.php

Question # 13

In the context of the CORS (Cross-origin resource sharing) misconfiguration, which of the following statements is true?

A.

CORS is exploitable if the value of the HTTP headers are Access-Control-Allow-Origin: * and Access-Control-Allow-Credentials: true

B.

CORS is exploitable if the value of the HTTP headers are Access-Control-Allow-Origin: * and Access-Control-Allow-Credentials: false

C.

CORS is exploitable if the value of the HTTP headers is Access-Control-Allow-Origin: * and the value of the Access-Control-Allow-Credentials header is irrelevant

D.

All of the above

Question # 14

A website administrator forgot to renew the TLS certificate on time and as a result, the application is now displaying a TLS error message. However, on closer inspection, it appears that the error is due to the TLS certificate expiry.

Which of the following is correct?

A.

There is no urgency to renew the certificate as the communication is still over TLS

B.

There is an urgency to renew the certificate as the users of the website may get conditioned to ignore TLS warnings and therefore ignore a legitimate warning which could be a real Man-in-the-Middle attack

Question # 15

You found the xmrpc.php endpoint while performing a security assessment on a web application. The target application is most likely using which of the following Content Management Systems (CMS)?

A.

WordPress

B.

Drupal

C.

Both A and B

D.

None of the above

Question # 16

Which of the following is NOT an asymmetric key encryption algorithm?

A.

AES

B.

RSA

C.

Diffie-Hellman

D.

DSA

Question # 17

Which of the following is NOT a symmetric key encryption algorithm?

A.

RC4

B.

AES

C.

DES

D.

RSA

Question # 18

What is the full form of SAML?

A.

Security Assertion Markup Language

B.

Security Authorization Markup Language

C.

Security Assertion Management Language

D.

Secure Authentication Markup Language

Go to page: