Question 6

Which of the following would MOST likely be included in the final report of a static application-security test that was written with a team of application developers as the intended audience?
  • Question 7

    A Chief Information Security Officer wants a penetration tester to evaluate the security awareness level of the company's employees.
    Which of the following tools can help the tester achieve this goal?
  • Question 8

    A penetration tester is starting an assessment but only has publicly available information about the target company. The client is aware of this exercise and is preparing for the test.
    Which of the following describes the scope of the assessment?
  • Question 9

    Which of the following web-application security risks are part of the OWASP Top 10 v2017? (Choose two.)
  • Question 10

    A penetration tester needs to perform a test on a finance system that is PCI DSS v3.2.1 compliant. Which of the following is the MINIMUM frequency to complete the scan of the system?