nerdexam
CompTIA

CAS-003 · Question #88

Company XYZ has purchased and is now deploying a new HTML5 application. The company wants to hire a penetration tester to evaluate the security of the client and server components of the proprietary…

The correct answer is C. Local proxy D. Fuzzer. C: Local proxy will work by proxying traffic between the web client and the web server. This is a tool that can be put to good effect in this case. D: Fuzzing is another form of blackbox testing and works by feeding a program multiple input iterations that are specially written…

Enterprise Security Operations

Question

Company XYZ has purchased and is now deploying a new HTML5 application. The company wants to hire a penetration tester to evaluate the security of the client and server components of the proprietary web application before launch. Which of the following is the penetration tester MOST likely to use while performing black box testing of the security of the company's purchased application? (Select TWO).

Options

  • ACode review
  • BSandbox
  • CLocal proxy
  • DFuzzer
  • EPort scanner

How the community answered

(41 responses)
  • A
    10% (4)
  • B
    2% (1)
  • C
    76% (31)
  • E
    12% (5)

Explanation

C: Local proxy will work by proxying traffic between the web client and the web server. This is a tool that can be put to good effect in this case. D: Fuzzing is another form of blackbox testing and works by feeding a program multiple input iterations that are specially written to trigger an internal error that might indicate a bug and crash

Topics

#penetration testing#black box testing#web application security#fuzzing

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice