nerdexam
EC-Council

312-50V13 · Question #431

An organization decided to harden its security against web-application and web-server attacks. John, a security personnel in the organization, employed a security scanner to automate web…

The correct answer is B. Syhunt Hybrid. Explanation Syhunt Hybrid (Option B) is a web application security scanner specifically designed to automate vulnerability testing for web applications and web servers, with built-in detection capabilities for XSS, SQL injection, directory traversal, command execution attempts…

Submitted by takeshi77· Mar 6, 2026Hacking Web Applications

Question

An organization decided to harden its security against web-application and web-server attacks. John, a security personnel in the organization, employed a security scanner to automate web- application security testing and to guard the organization's web infrastructure against web- application threats. Using that tool, he also wants to detect XSS, directory transversal problems, fault injection, SQL injection, attempts to execute commands, and several other attacks. Which of the following security scanners will help John perform the above task?

Options

  • AAlienVault®OSSIMTM
  • BSyhunt Hybrid
  • CSaleae Logic Analyzer
  • DCisco ASA

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    74% (20)
  • C
    7% (2)
  • D
    15% (4)

Explanation

Explanation

Syhunt Hybrid (Option B) is a web application security scanner specifically designed to automate vulnerability testing for web applications and web servers, with built-in detection capabilities for XSS, SQL injection, directory traversal, command execution attempts, fault injection, and numerous other web-based attack vectors - making it a perfect fit for John's requirements.

Option A (AlienVault® OSSIM™) is incorrect because it is a Security Information and Event Management (SIEM) platform focused on log correlation, threat intelligence, and network monitoring - not a dedicated web application vulnerability scanner. Option C (Saleae Logic Analyzer) is a hardware tool used for analyzing digital signals and protocols in electronics, having no relevance to web security testing whatsoever. Option D (Cisco ASA) is a network firewall/VPN appliance that provides perimeter security but does not perform active web application vulnerability scanning.

Memory Tip: Think "Syhunt = Hunt for web app sins" - the name contains "hunt," which reflects its purpose of actively hunting down web application vulnerabilities like XSS and SQL injection. If the question describes automated scanning for multiple web application attack types simultaneously, look for a dedicated web app scanner and eliminate SIEM tools, hardware analyzers, and firewalls immediately.

Topics

#Web Application Security#Vulnerability Scanning#Security Scanners

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice