nerdexam
CompTIA

CAS-003 · Question #140

Joe, a penetration tester, is tasked with testing the security robustness of the protocol between a mobile web application and a RESTful application server. Which of the following security tools…

The correct answer is D. HTTP interceptor E. Vulnerability scanner. Communications between a mobile web application and a RESTful application server will use the HTTP protocol. To capture the HTTP communications for analysis, you should use an HTTP To assess the security of the application server itself, you should use a vulnerability scanner…

Enterprise Security Operations

Question

Joe, a penetration tester, is tasked with testing the security robustness of the protocol between a mobile web application and a RESTful application server. Which of the following security tools would be required to assess the security between the mobile web application and the RESTful application server? (Select TWO).

Options

  • AJailbroken mobile device
  • BReconnaissance tools
  • CNetwork enumerator
  • DHTTP interceptor
  • EVulnerability scanner
  • FPassword cracker

How the community answered

(13 responses)
  • A
    15% (2)
  • C
    8% (1)
  • D
    77% (10)

Explanation

Communications between a mobile web application and a RESTful application server will use the HTTP protocol. To capture the HTTP communications for analysis, you should use an HTTP To assess the security of the application server itself, you should use a vulnerability scanner. A vulnerability scan is the automated process of proactively identifying security vulnerabilities of computing systems in a network in order to determine if and where a system can be exploited and/or threatened. While public servers are important for communication and data transfer over the Internet, they open the door to potential security breaches by threat agents, such as malicious hackers. Vulnerability scanning employs software that seeks out security flaws based on a database of known flaws, testing systems for the occurrence of these flaws and generating a report of the findings that an individual or an enterprise can use to tighten the network's security. Vulnerability scanning typically refers to the scanning of systems that are connected to the Internet but can also refer to system audits on internal networks that are not connected to the Internet in order to assess the threat of rogue software or malicious employees in an enterprise.

Topics

#mobile security#REST API testing#HTTP interception#vulnerability scanning

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice