WAS01-03 WAF-as-a-Service -
Foundation
What do you want to permit Credential Attack Protection?
The X-Frame header desires to be gift within the response.
The URL of the web page that contains the login fields.
*The names of the username and password parameters.*
Access to the person database.
How are you able to deny metacharacters for a particular parameter?
By growing a parameter profile for said parameter in App Profiles and denying the
metacharacter.
*Metacharacters for specific parameters cannot be denied.*
By denying the parameter within the Parameter Protection thing.
If WaaS is in block mode and a request causes a security violation
... It will be checked by way of all different components, earlier than it is dropped.
*... The request may be blocked at once.*
... The request will reach the backend server.
WaaS Access logs contain records on who logged into your WaaS account.
Fake
Where can you check if there's a trouble with WaaS?
Repute.Barracuda.Com
, An application in WaaS ...
... Is publicly on hand thru the public IP address of the net server. (1,2,three,4)
.. Can be used to exchange from block to display mode. (1,2,3,four)
... Is publicly reachable via the endpoints CNAME document. (2,three)
... Is used to outline the security settings for your net utility. (2)
(F)
Cookie encryption...
*... Can't be used if your consumer-facet scripts need to get entry to the cookie.*
*... Prevents customers from viewing cookies.*
*... Prevents attackers from tampering cookies.*
WaaS simplest blocks assaults if the application is set to block mode.
False, all assaults are blocked even supposing block mode isn't enabled.
*True, however cookie safety is enforced even though the utility isn't in block mode. (If the
cookie security thing is enabled)*
True, assaults are simplest blocked if WaaS is set to block.
What occurs if cookie signing is used and cookie verification fails?
*Cookies will be eliminated before forwarding the request to the backend server.*
The request can be dropped.
What does reaction cloaking do?
*It replaces headers and return codes.*
*It rewrites the response coming from the server.*
*It prevents attackers from gaining facts about the net software that can be used in a
subsequent assault.*
Foundation
What do you want to permit Credential Attack Protection?
The X-Frame header desires to be gift within the response.
The URL of the web page that contains the login fields.
*The names of the username and password parameters.*
Access to the person database.
How are you able to deny metacharacters for a particular parameter?
By growing a parameter profile for said parameter in App Profiles and denying the
metacharacter.
*Metacharacters for specific parameters cannot be denied.*
By denying the parameter within the Parameter Protection thing.
If WaaS is in block mode and a request causes a security violation
... It will be checked by way of all different components, earlier than it is dropped.
*... The request may be blocked at once.*
... The request will reach the backend server.
WaaS Access logs contain records on who logged into your WaaS account.
Fake
Where can you check if there's a trouble with WaaS?
Repute.Barracuda.Com
, An application in WaaS ...
... Is publicly on hand thru the public IP address of the net server. (1,2,three,4)
.. Can be used to exchange from block to display mode. (1,2,3,four)
... Is publicly reachable via the endpoints CNAME document. (2,three)
... Is used to outline the security settings for your net utility. (2)
(F)
Cookie encryption...
*... Can't be used if your consumer-facet scripts need to get entry to the cookie.*
*... Prevents customers from viewing cookies.*
*... Prevents attackers from tampering cookies.*
WaaS simplest blocks assaults if the application is set to block mode.
False, all assaults are blocked even supposing block mode isn't enabled.
*True, however cookie safety is enforced even though the utility isn't in block mode. (If the
cookie security thing is enabled)*
True, assaults are simplest blocked if WaaS is set to block.
What occurs if cookie signing is used and cookie verification fails?
*Cookies will be eliminated before forwarding the request to the backend server.*
The request can be dropped.
What does reaction cloaking do?
*It replaces headers and return codes.*
*It rewrites the response coming from the server.*
*It prevents attackers from gaining facts about the net software that can be used in a
subsequent assault.*