- Which of the following is not the input of whitebox review?
- Source code
- Threat-modeling documents
- Automated static code analysis results
- Antivirus scanning results
- What are the tools doxygen and naturaldocs used for?
- Generating documents directly from source code
- Static code scanning
- Dynamic code scanning
- Reverse engineering
- Which of the following are high-risk modules?
- Authentication
- Authorization
- API interfaces
- All of the above
- Which one of the following APIs is not related to buffer overflow?
- strcpy
- strncat
- memcpy
- fwrite
- What can cause missing authentication?
- The uses of partial URL match API to determine the need for authentication such as StartsWith and EndsWith
- No path canonicalization before validation
- No data normalization before validation
- All of the above
Germany
Slovakia
Canada
Brazil
Singapore
Hungary
Philippines
Mexico
Thailand
Ukraine
Luxembourg
Estonia
Lithuania
Norway
Chile
United States
Great Britain
India
Spain
South Korea
Ecuador
Colombia
Taiwan
Switzerland
Indonesia
Cyprus
Denmark
Finland
Poland
Malta
Czechia
New Zealand
Austria
Turkey
France
Sweden
Italy
Egypt
Belgium
Portugal
Slovenia
Ireland
Romania
Greece
Argentina
Malaysia
South Africa
Netherlands
Bulgaria
Latvia
Australia
Japan
Russia