Qualys Web Application Scanning (EXAM)
// // // //
Questions With Answers
// // // //
The Malware Monitoring option should only be enabled for:
// // // // // // // //
(A) Applications with a "malware" tag
// // // // //
(B) Internal facing applications
// // //
(C) External facing applications
// // //
(D) Both internal and external facing applications - CORRECT
// // // // // // // //
ANSWERS(S)✔✔(C) External facing applications
// // // //
Where can you "Ignore" a vulnerability for a Web Application?
// // // // // // // // //
(select two) (Choose all that apply)
// // // // // //
(A) Scorecard Report
// //
(B) Scan Report
// //
(C) Web Application Report
// // //
(D) Detections Tab - CORRECT ANSWERS(S)✔✔(B) Scan Report
// // // // // // //
(D) Detection Tab
// //
A Search List contains a list of:
// // // // // //
,(A) Username/Password combinations
// //
(B) QIDs from the Qualys KnowledgeBase
// // // // //
(C) Crawling hints
// //
(D) Common input parameters - CORRECT ANSWERS(S)✔✔(B)
// // // // // //
QIDs from the QualysBase
// // // //
When launching a Web Application Scan, you have the option to
// // // // // // // // // //
override some default settings. Which of the following options
// // // // // // // // //
can NOT be overridden?
// // // //
(A) Option Profile
// //
(B) Crawl Scope
// //
(C) Scanner Appliance
// //
(D) Authentication Record - CORRECT ANSWERS(S)✔✔(D)
// // // // //
Authentication Record
// //
What attack proxies can you integrate with Qualys WAS?
// // // // // // // //
(A) BURP
//
(B) W3af
//
(C) ZAP
//
, (D) WebScarab - CORRECT ANSWERS(S)✔✔(A) BURP
// // // // //
How can you get your scan to follow a business workflow (such
// // // // // // // // // // //
as a shopping cart transaction)?
// // // // //
(A) Use a Selenium Script to record and replay the workflow
// // // // // // // // // //
(B) Use a Custom Authentication Record
// // // // //
(C) Use a Crawl Exclusion List
// // // // //
(D) Use DNS Override - CORRECT ANSWERS(S)✔✔(A) Use a
// // // // // // // //
Selenium Script to record and replay the workflow
// // // // // // // //
Using the "Crawling Hints" setting, WAS can crawl all links and
// // // // // // // // // //
directories found in: (select two) (Choose all that apply)
// // // // // // // // //
(A) Index.html
//
(B) Sitemap.xml
//
(C) Robots.txt
//
(D) default.css - CORRECT ANSWERS(S)✔✔(B) Sitemap.xml
// // // // //
(C) Robots.txt
//
The Explicit URLs to Crawl field may contain (select two): (Select
// // // // // // // // // //
all that apply)
// // //
// // // //
Questions With Answers
// // // //
The Malware Monitoring option should only be enabled for:
// // // // // // // //
(A) Applications with a "malware" tag
// // // // //
(B) Internal facing applications
// // //
(C) External facing applications
// // //
(D) Both internal and external facing applications - CORRECT
// // // // // // // //
ANSWERS(S)✔✔(C) External facing applications
// // // //
Where can you "Ignore" a vulnerability for a Web Application?
// // // // // // // // //
(select two) (Choose all that apply)
// // // // // //
(A) Scorecard Report
// //
(B) Scan Report
// //
(C) Web Application Report
// // //
(D) Detections Tab - CORRECT ANSWERS(S)✔✔(B) Scan Report
// // // // // // //
(D) Detection Tab
// //
A Search List contains a list of:
// // // // // //
,(A) Username/Password combinations
// //
(B) QIDs from the Qualys KnowledgeBase
// // // // //
(C) Crawling hints
// //
(D) Common input parameters - CORRECT ANSWERS(S)✔✔(B)
// // // // // //
QIDs from the QualysBase
// // // //
When launching a Web Application Scan, you have the option to
// // // // // // // // // //
override some default settings. Which of the following options
// // // // // // // // //
can NOT be overridden?
// // // //
(A) Option Profile
// //
(B) Crawl Scope
// //
(C) Scanner Appliance
// //
(D) Authentication Record - CORRECT ANSWERS(S)✔✔(D)
// // // // //
Authentication Record
// //
What attack proxies can you integrate with Qualys WAS?
// // // // // // // //
(A) BURP
//
(B) W3af
//
(C) ZAP
//
, (D) WebScarab - CORRECT ANSWERS(S)✔✔(A) BURP
// // // // //
How can you get your scan to follow a business workflow (such
// // // // // // // // // // //
as a shopping cart transaction)?
// // // // //
(A) Use a Selenium Script to record and replay the workflow
// // // // // // // // // //
(B) Use a Custom Authentication Record
// // // // //
(C) Use a Crawl Exclusion List
// // // // //
(D) Use DNS Override - CORRECT ANSWERS(S)✔✔(A) Use a
// // // // // // // //
Selenium Script to record and replay the workflow
// // // // // // // //
Using the "Crawling Hints" setting, WAS can crawl all links and
// // // // // // // // // //
directories found in: (select two) (Choose all that apply)
// // // // // // // // //
(A) Index.html
//
(B) Sitemap.xml
//
(C) Robots.txt
//
(D) default.css - CORRECT ANSWERS(S)✔✔(B) Sitemap.xml
// // // // //
(C) Robots.txt
//
The Explicit URLs to Crawl field may contain (select two): (Select
// // // // // // // // // //
all that apply)
// // //