NO.1 Which of the following statements is TRUE of black box testing?
A. Only the source code and the design documents are known to the test planner.
B. Only the functional specifications are known to the test planner.
C. Only the source code and functional specifications are known to the test planner.
D. Only the design documents and the functional specifications are known to the test planner.
Answer: B


NO.2 Which of the following command line tools can be used in the reconnaisance phase of a
network vulnerability assessment?
A. ipconfig
B. ifconfig
C. dig
D. nbtstat
Answer: C

NO.3 The FIRST step in building a firewall is to
A. assign the roles and responsibilities of the firewall administrators.
B. perform a risk analysis to identify issues to be addressed.
C. identify mechanisms to encourage compliance with the policy.
D. define the intended audience who will read the firewall policy.
Answer: B


NO.4 Which Hyper Text Markup Language 5 (HTML5) option presents a security challenge for
network data leakage prevention and/or monitoring?
A. Web Interface Definition Language (IDL)
B. Cross Origin Resource Sharing (CORS)
C. WebSockets
D. Document Object Model (DOM) trees
Answer: C



