IBM
C2150-810 · Question #42
You are reviewing a thick client application and come upon File Injection findings in a function that opens zip files and extracts data from them, but the customer you are working with tells you…
The correct answer is B. Source section. See the full explanation below for the reasoning.
Question
You are reviewing a thick client application and come upon File Injection findings in a function that opens zip files and extracts data from them, but the customer you are working with tells you that the data is sanitized using a method mySanitizer.validateZip{..). You confirm this and decide to remove this vulnerability and other File injection findings with sanitized data using the Remove functionality of the Trace section in the Filter Editor. In which area of the Trace Rule Entry dialog would you add mySanitizer.validateZip(..) method?
Options
- ASink section
- BSource section
- CRequired Calls section
- DProhibited Calls section
How the community answered
(48 responses)- A6% (3)
- B77% (37)
- C13% (6)
- D4% (2)
Community Discussion
No community discussion yet for this question.