IBM C2150-810 시험 개요:
| 인증 벤더: | IBM |
| 시험명: | IBM Security AppScan Source Edition 구현 |
| 시험 번호: | C2150-810 |
| 지원 언어: | English |
| 시험 시간: | 90 minutes |
| 실제 시험 문항 수: | 50 - 60 |
| 응시료: | 약 200달러 USD (지역에 따라 상이함) |
| 합격 점수: | 70% |
| 시험 형식: | 객관식, 시나리오 기반, 드래그 앤 드롭 |
| 관련 자격증: | IBM Certified Deployment Professional - Security |
| 자격증 유효 기간: | 3년 |
| 권장 교육: | IBM Security AppScan Source Edition 문서 IBM 교육 및 기술 역량 강화 |
| 시험 등록: | IBM 인증 등록 Pearson VUE IBM 시험 일정 예약 |
| 샘플 문제: | IBM C2150-810 샘플 문제 |
| 응시 방법: | 온라인 감독 방식(OnVUE) 또는 Pearson VUE 공인 시험 센터에서의 대면 응시 |
| 전제 조건: | 공식적인 사전 요건은 없음; IBM Security AppScan Source Edition에 대한 실무 경험 및 애플리케이션 보안 관련 지식 보유 권장 |
| 공식 요강 URL: | https://www.ibm.com/certify/exams/C2150-810 |
IBM C2150-810 시험 요강 주제:
| 섹션 | 비중 | 목표 |
|---|---|---|
| 주제 1: 검사 구성 및 실행 | 25% | - 검사 프로젝트 생성 및 구성 - 프로그래밍 언어 및 프레임워크 지원 - 검사 규칙 및 규칙 세트 구성 - GUI 및 명령줄을 통한 검사 실행 |
| 주제 2: 설치 및 구성 | 25% | - 서버 및 클라이언트 구성 요소 설치 - 사용자 역할 및 권한 설정 - IDE와의 통합 구성 - 데이터베이스 및 보안 설정 구성 |
| 주제 3: 아키텍처 및 계획 | 20% | - 시스템 요구 사항 및 규모 산정 - 라이선스 및 배포 모델 - AppScan Source Edition 구성 요소 이해 |
| 주제 4: 결과 분석 및 취약점 관리 | 20% | - 검출 내용 및 심각도 수준 해석 - 결함 추적 시스템과의 통합 - 추적 분석 및 규칙 사용자 정의 - 취약점 필터링, 우선순위 지정 및 상태 표시 |
| 주제 5: 보고 및 관리 | 10% | - 보고서 생성 및 내보내기 - 백업, 복원 및 유지 관리 - 일반적인 문제 해결 |
최신 IBM Certified Deployment Professional C2150-810 무료샘플문제
1. What is the difference between AppScan Source Developer and AppScan Source Remediation licenses?
A) AppScan Source Developer allows you to run scans from CLI, while AppScan Source Remediation allows you only to remediate security issues.
B) AppScan Source Developer allows you only to remediate security issues, while AppScan Source Remediation allows you to run scans from within the IDE.
C) AppScan Source for Remediation supports only Visual Studio while AppScan Source for Developer supports both Eclipse and Visual Studio.
D) AppScan Source Developer allows you to run scans from within the IDE, while AppScan Source Remediation allows you only to remediate security issues.
2. How are safe sources dismissed during the triage process?
A) Set a Vulnerability Type filter to remove any findings that originated from the safe source.
B) Set all the sinks originated from the safe source to NST.
C) Set a Classification filter to remove any findings that originated from the safe source.
D) Set a Trace filter to remove any findings that originated from the safe source.
3. You are analyzing a client-server application that has "thick" clients that run on Windows and Android. You come across several Remote Command Execution findings with data originating from several different Sources. The customer you are working with is worried about the developers pushing back on low priority findings, so you need to remove those originating from sources that pose the lowest risk.
Which Sources pose the lowest risk?
A) WebService.performOperation(...)
B) RPCHandler.performOperation(...)
C) SqlDB.getValue(...)
D) ZipCrypto.extract(...)
E) NativeCode.performOperation(...)
4. You are reviewing a thick client application and come upon File Injection findings in a function that opens zip files and extracts data from them, but the customer you are working with tells you that the data is sanitized using a method mySanitizer.validateZip(..). You confirm this and decideto remove this vulnerability and other File Injection findings with sanitized data using the Remove functionality of the Trace section in the Filter Editor.
What do you need to do in the Trace Rule Entry dialog to ensure that the rule you create applies only to this application's zip extractor and not all File Inclusion findings?
A) Add validateZipO to the Required Calls section.
B) Specify File Inclusion as Sink property.
C) Specify Sink method name.
D) Specify File Inclusion as Source property.
E) Add validateZipO to the Prohibited Calls section.
5. Which statement is true about AppScan Source's defect tracking system integration?
A) It can be used to submit defects during unattended scans using AppScan Source for Automation.
B) It can be used to update finding status in AppScan Source from a defect entry.
C) It can be used to submit one or more findings in a single defect entry.
D) It can be used to submit one or more bundles in a single defect entry.
질문과 대답:
| 질문 # 1 정답: C | 질문 # 2 정답: A | 질문 # 3 정답: A | 질문 # 4 정답: B | 질문 # 5 정답: D |














972 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
