フリー問題

Certified Tester Security Tester (CT-SEC) v1.0 のフリー問題 3 / 20 問目

問題文

A team is about to test a new mobile banking front end. It accepts a numeric passcode, keeps a session token on the handset, and calls a public interface over the internet. Which set of security test objectives is drawn correctly from the function, from the technology and from the known weaknesses?

選択肢

  1. Verify that the passcode rule holds the stated strength, that the token store resists a stolen handset, and that the input filter blocks a crafted query before the general deployment.
  2. Verify that the passcode field holds the printed hint, that the token store records a device serial, and that the input filter blocks a duplicate query before the live deployment.
  3. Verify that the passcode entry holds the vendor default, that the token store mirrors a backup server, and that the input filter blocks a foreign query before the general deployment.
  4. Verify that the passcode screen holds the agreed colors, that the token store survives a slow handset, and that the input filter blocks a repeated query before the commercial deployment.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。