F5
F50-536 · Question #36
A security audit has determined that your web application is vulnerable to a cross-site scripting attack. Which of the following measures are appropriate when building a security policy? (Choose 2)
The correct answer is B. Attack signature sets must be applied to any user input parameters. D. Parameter data entered for flow-level parameters must allow some meta-characters but not. See the full explanation below for the reasoning.
Question
A security audit has determined that your web application is vulnerable to a cross-site scripting attack. Which of the following measures are appropriate when building a security policy? (Choose 2)
Options
- ACookie length must be restricted to 1024 bytes.
- BAttack signature sets must be applied to any user input parameters.
- CParameter data entered for explicit objects must be checked for minimum and maximum
- DParameter data entered for flow-level parameters must allow some meta-characters but not
How the community answered
(32 responses)- A9% (3)
- B75% (24)
- C16% (5)
Community Discussion
No community discussion yet for this question.