フリー問題

Certified Tester Security Test Engineer (CT-STE) v1.0.1 のフリー問題 20 / 20 問目

問題文

A tool reads uncompiled source, the libraries it references and the configuration files, then compares them against its own repository of known weaknesses for that language. Nothing has to be running. Which category does it fall under, and what does it require?

選択肢

  1. A tool of this description falls under the dynamic analysis category, and the precondition it imposes on the vulnerability run is the deployed service instance.
  2. A tool of this description falls under the static analysis category, and the precondition it imposes on the vulnerability run is the granted source access.
  3. A tool of this description falls under the composition analysis category, and the precondition it imposes on the vulnerability run is the resolved dependency manifest.
  4. A tool of this description falls under the interactive analysis category, and the precondition it imposes on the vulnerability run is the installed runtime agent.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。