問題文
A team is about to test a new mobile banking front end. It accepts a numeric passcode, keeps a session token on the handset, and calls a public interface over the internet. Which set of security test objectives is drawn correctly from the function, from the technology and from the known weaknesses?
選択肢
- Verify that the passcode rule holds the stated strength, that the token store resists a stolen handset, and that the input filter blocks a crafted query before the general deployment.
- Verify that the passcode field holds the printed hint, that the token store records a device serial, and that the input filter blocks a duplicate query before the live deployment.
- Verify that the passcode entry holds the vendor default, that the token store mirrors a backup server, and that the input filter blocks a foreign query before the general deployment.
- Verify that the passcode screen holds the agreed colors, that the token store survives a slow handset, and that the input filter blocks a repeated query before the commercial deployment.