IBM C2150-199 Exam Overview:
| Certification Vendor: | IBM |
| Exam Name: | IBM Security AppScan Standard Edition Implementation v8.7 |
| Exam Number: | C2150-199 |
| Real Exam Qty: | 55-56 |
| Available Languages: | English |
| Related Certifications: | IBM Certified Specialist - Rational AppScan Standard Edition IBM Certified Deployment Professional |
| Exam Format: | Multiple Choice |
| Passing Score: | 65% |
| Certificate Validity Period: | As specified by IBM (renewal possible) |
| Exam Price: | 100 USD (approx.) |
| Exam Duration: | 120 minutes |
| Sample Questions: | IBM C2150-199 Sample Questions |
| Exam Way: | Delivered through Pearson VUE test centers or online (OnVUE) proctored delivery |
| Pre Condition: | Familiarity with IBM Security AppScan Standard Edition and web application security basics |
| Official Syllabus URL: | https://www.pearsonvue.com/us/en/ibm.html |
IBM C2150-199 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Scan Setup | 50% | |
| Topic 2: Application Testing | 9% | |
| Topic 3: Exploration Techniques | 13% | - Manual Exploration - Exploring Application |
| Topic 4: Analyzing Results | 16% | |
| Topic 5: Installation | 4% |
IBM Security AppScan Standard Edition Implementation v8.7 Sample Questions:
1. Which situation presents a valid reason for reducing the severity ofvulnerability?
A) A High severity Cross-Site Scripting vulnerability is confirmed to be a Reflected XSS and would require user authentication to be exploited.
B) A High severity SQL Injection vulnerability should be reduced when the affected database is read only.
C) A High severity Unencrypted Login Request vulnerability should be reduced when the application is using a database that is encrypted with Triple DES (Data Encryption Standard) and a 168 bit key.
D) A Medium severity Link Injection vulnerability should be reduced when it only occurs on a login page.
2. How do you remove sensitive information from the scan logs?
A) Disable request/response logging
B) Enable Sanitize logs in advanced configuration
C) Use the Customize Scan Log to disable sensitive information
D) Disable scan logs
3. Given the following: Security Issues
Which type of report is this an example of?
A) Regulatory compliance report
B) Security report
C) Delta analysis report
D) Industry standard report
4. Which log file would be useful in verifying whether or not a particular security test was executed during a test?
A) Scan log
B) Update log
C) Security log
D) AppScan log
5. Which statement is true about URL settings in Automatic Form Fill?
A) If a URL is not provided for a value, this value will not be used.
B) If a URL is provided for a value, this value will be used only for parameters in this URL and if match type is Complete.
C) If a URL is not provided for a value, this value will be used only if match type is Complete.
D) If a URL is provided for a value, this value will be used only for parameters in this URL.
Solutions:
| Question # 1 Answer: D | Question # 2 Answer: B | Question # 3 Answer: C | Question # 4 Answer: B | Question # 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Rosemary

