- Which of the following is not the input of whitebox review?
- Source code
- Threat-modeling documents
- Automated static code analysis results
- Antivirus scanning results
- What are the tools doxygen and naturaldocs used for?
- Generating documents directly from source code
- Static code scanning
- Dynamic code scanning
- Reverse engineering
- Which of the following are high-risk modules?
- Authentication
- Authorization
- API interfaces
- All of the above
- Which one of the following APIs is not related to buffer overflow?
- strcpy
- strncat
- memcpy
- fwrite
- What can cause missing authentication?
- The uses of partial URL match API to determine the need for authentication such as StartsWith and EndsWith
- No path canonicalization before validation
- No data normalization before validation
- All of the above
United States
Great Britain
India
Germany
France
Canada
Russia
Spain
Brazil
Australia
Singapore
Hungary
Ukraine
Luxembourg
Estonia
Lithuania
South Korea
Turkey
Switzerland
Colombia
Taiwan
Chile
Norway
Ecuador
Indonesia
New Zealand
Cyprus
Denmark
Finland
Poland
Malta
Czechia
Austria
Sweden
Italy
Egypt
Belgium
Portugal
Slovenia
Ireland
Romania
Greece
Argentina
Netherlands
Bulgaria
Latvia
South Africa
Malaysia
Japan
Slovakia
Philippines
Mexico
Thailand