312-96 Exam Question 16

Which of the following can be derived from abuse cases to elicit security requirements for software system?
  • 312-96 Exam Question 17

    Thomas is not skilled in secure coding. He neither underwent secure coding training nor is aware of the consequences of insecure coding. One day, he wrote code as shown in the following screenshot. He passed 'false' parameter to setHttpOnly() method that may result in the existence of a certain type of vulnerability. Identify the attack that could exploit the vulnerability in the above case.
  • 312-96 Exam Question 18

    Which of the following DFD component is used to represent the change in privilege levels?
  • 312-96 Exam Question 19

    The developer wants to remove the HttpSessionobject and its values from the client' system.
    Which of the following method should he use for the above purpose?
  • 312-96 Exam Question 20

    The threat modeling phase where applications are decomposed and their entry points are reviewed from an attacker's perspective is known as ________