Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free The SecOps Group CAP Practice Exam with Questions & Answers | Set: 2

Questions 11

Multifactor authentication will NOT be able to prevent:

Options:
A.

Cross-Site Scripting Vulnerability

B.

Cross-Site Request Forgery Vulnerability

C.

Path Traversal Vulnerability

D.

All of the above

The SecOps Group CAP Premium Access
Questions 12

The application is vulnerable to Cross-Site Scripting. Which of the following exploitation is NOT possible at all?

Options:
A.

Steal the user's session identifier stored on a non HttpOnly cookie

B.

Steal the contents from the web page

C.

Steal the contents from the application's database

D.

Steal the contents from the user's keystrokes using keyloggers

Questions 13

Which of the following Google Dorks can be used for finding directory listing on victim-app.com?

Options:
A.

intitle:"Index of" site:victim-app.com

B.

intext:"Index of" site:victim-app.com

C.

Both A and B

D.

None of the above

Questions 14

In the context of the infamous log4j vulnerability (CVE-2021-44228), which vulnerability is exploited in the backend to achieve Remote Code Execution?

Options:
A.

JNDI Injection

B.

JNDI Injection

C.

JNDI Injection

D.

None of the above

Questions 15

Under the same-origin policy (also SOP), a web browser permits scripts contained in a web page to access data in another web page, but only if both web pages have the same origin. Which of the following pages are in the same origin as that of the below URL?

http://www.example.com/dir/page2.html

    http://www.example.com/dir/other.html

    http://www.example.com:81/dir/other.html

    http://www.example.com/dir/other.html

    http://en.example.com/dir/other.html

Options:
A.

1 Only

B.

1 and 2

C.

1, 3 and 4

D.

None of the above

Questions 16

Which of the following attributes is NOT used to secure the cookie?

Options:
A.

HttpOnly

B.

Secure

C.

Restrict

D.

Same-Site

Questions 17

In the context of the CORS (Cross-origin resource sharing) misconfiguration, which of the following statements is true?

Options:
A.

CORS is exploitable if the value of the HTTP headers are Access-Control-Allow-Origin: * and Access-Control-Allow-Credentials: true

B.

CORS is exploitable if the value of the HTTP headers are Access-Control-Allow-Origin: * and Access-Control-Allow-Credentials: false

C.

CORS is exploitable if the value of the HTTP headers is Access-Control-Allow-Origin: * and the value of the Access-Control-Allow-Credentials header is irrelevant

D.

All of the above

Questions 18

Which of the following is a common attack in the context of SAML security?

Options:
A.

XML Signature Wrapping Attack

B.

XML External Entity Injection

C.

Assertion Replay Attack

D.

All of the above

Exam Code: CAP
Certification Provider: The SecOps Group
Exam Name: Certified AppSec Practitioner Exam
Last Update: Jul 11, 2025
Questions: 60
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42