IBM
C2150-199 · Question #49
An AppScan user captured the following URLs during a recorded login: The same user selected an in-session detection pattern of "Hello John Smith". Given that the "Hello John Smith" string only…
The correct answer is D. Yes, AppScan will send the request for the in-session page and detect the in-session pattern. See the full explanation below for the reasoning.
Question
An AppScan user captured the following URLs during a recorded login:
The same user selected an in-session detection pattern of "Hello John Smith". Given that the "Hello John Smith" string only appears on the in-session page (main.jsp). Will AppScan be able to stay in-session and successfully scan the application?
Options
- ANo. the in-session page is HTTPS and cannot be interpreted by AppScan.
- BNo, the in-session detection pattern needs to appear on every page of the application.
- CYes, AppScan does not check the in-session pattern as a means of validating the session.
- DYes, AppScan will send the request for the in-session page and detect the in-session pattern.
How the community answered
(20 responses)- A10% (2)
- C5% (1)
- D85% (17)
Community Discussion
No community discussion yet for this question.