nerdexam
IBM

C2150-810 · Question #50

You are reviewing a thick client application and come upon File Injection findings in a function that opens zip files and extracts data from them, but the customer you are working with tells you…

The correct answer is B. Specify File Inclusion as Sink property. See the full explanation below for the reasoning.

Question

You are reviewing a thick client application and come upon File Injection findings in a function that opens zip files and extracts data from them, but the customer you are working with tells you that the data is sanitized using a method mySanitizer.validateZip(..). You confirm this and decideto remove this vulnerability and other File Injection findings with sanitized data using the Remove functionality of the Trace section in the Filter Editor. What do you need to do in the Trace Rule Entry dialog to ensure that the rule you create applies only to this application's zip extractor and not all File Inclusion findings?

Options

  • ASpecify Sink method name.
  • BSpecify File Inclusion as Sink property.
  • CSpecify File Inclusion as Source property.
  • DAdd validateZipO to the Required Calls section.
  • EAdd validateZipO to the Prohibited Calls section.

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    72% (26)
  • C
    3% (1)
  • D
    8% (3)
  • E
    14% (5)

Community Discussion

No community discussion yet for this question.

Full C2150-810 Practice