Free 312-96 Exam Braindumps (page: 2)

Page 1 of 12

Sam, an application security engineer working in INFRA INC., was conducting a secure code review on an application developed in Java. He found that the developer has used a piece of code as shown in the following screenshot. Identify the security mistakes that the developer has coded?

  1. He is attempting to use client-side validation
  2. He is attempting to use whitelist input validation approach
  3. He is attempting to use regular expression for validation
  4. He is attempting to use blacklist input validation approach

Answer(s): D



Identify the type of attack depicted in the following figure.

  1. SQL Injection Attacks
  2. Session Fixation Attack
  3. Parameter Tampering Attack
  4. Denial-of-Service Attack

Answer(s): C



According to secure logging practices, programmers should ensure that logging processes are not disrupted by:

  1. Catching incorrect exceptions
  2. Multiple catching of incorrect exceptions
  3. Re-throwing incorrect exceptions
  4. Throwing incorrect exceptions

Answer(s): D



Which of the threat classification model is used to classify threats during threat modeling process?

  1. RED
  2. STRIDE
  3. DREAD
  4. SMART

Answer(s): B






Post your Comments and Discuss EC-Council 312-96 exam with other Community members:

312-96 Discussions & Posts