nerdexam
EC-Council

312-50V11 · Question #991

An organization decided to harden its security against web-application and web-server attacks. John, a security personnel in the organization, employed a security scanner to automate web…

The correct answer is B. ASyhunt Hybrid. ASyhunt Hybrid is a web application security scanner that automates detection of vulnerabilities including XSS, SQL injection, directory traversal, command injection, and fault injection.

Vulnerability Analysis

Question

An organization decided to harden its security against web-application and web-server attacks. John, a security personnel in the organization, employed a security scanner to automate web- application security testing and to guard the organization's web infrastructure against web- application threats. Using that tool, he also wants to detect XSS, directory transversal problems, fault injection, SQL injection, attempts to execute commands, and several other attacks. Which of the following security scanners will help John perform the above task?

Options

  • AAlienVault®OSSIMTM
  • BASyhunt Hybrid
  • CSaleae Logic Analyzer
  • DCisco ASA

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    90% (28)
  • D
    6% (2)

Why each option

ASyhunt Hybrid is a web application security scanner that automates detection of vulnerabilities including XSS, SQL injection, directory traversal, command injection, and fault injection.

AAlienVault®OSSIMTM

AlienVault OSSIM is an open-source Security Information and Event Management (SIEM) platform used for log aggregation and security event correlation, not for automated web application vulnerability scanning.

BASyhunt HybridCorrect

ASyhunt Hybrid is a web application security scanner and fuzzer designed to automate testing for a broad range of web vulnerabilities including cross-site scripting (XSS), SQL injection, directory traversal, command execution attempts, and fault injection. This directly satisfies John's requirement for a single tool that automates web-application security testing and guards against multiple classes of web-application threats simultaneously.

CSaleae Logic Analyzer

Saleae Logic Analyzer is a hardware device used for capturing and analyzing digital and analog signals in electronic circuits, which has no relevance to web application security testing.

DCisco ASA

Cisco ASA is a network firewall and VPN appliance that provides perimeter-level network security, not a web application scanner capable of detecting XSS, SQL injection, or directory traversal vulnerabilities.

Concept tested: Web application vulnerability scanner tool selection

Source: https://owasp.org/www-project-web-security-testing-guide/

Topics

#web application scanner#vulnerability scanning#XSS detection#SQL injection testing

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice